Palo Alto · Serving all of California

CALL US TODAY!

(650) 668-8000

How to Collect Unpaid Invoices California: Demand Letters, Small Claims, and Judgment Enforcement

how-to-collect-unpaid-invoices-california

TL;DR — Key Takeaways

  • CCPA small business requirements start with whether the statute reaches you at all, and for many small companies it does not. Civil Code section 1798.140(d)(1) defines a covered “business” by three thresholds, and none of them counts how many people you merely collect information from.
  • The volume threshold is about trading, not collecting: buying, selling or sharing the personal information of 100,000 or more consumers or households. The others are revenue over $25,000,000 (thresholds stated as of drafting) in the preceding calendar year, or deriving 50 percent or more of annual revenues from selling or sharing personal information.
  • Every dollar figure in the Act is indexed and published off-code. Section 1798.199.95(d) requires the California Privacy Protection Agency to adjust the revenue threshold, the statutory damages and the administrative fines every odd-numbered year for CPI, post the adjusted figures on its website by January 15, and do so outside the Administrative Procedure Act. The numbers printed in the Civil Code are the un-indexed baseline.
  • The “Do Not Sell or Share My Personal Information” link is required by section 1798.135 only of a business that sells or shares personal information, or uses sensitive personal information beyond authorized purposes – and a business that honours an opt-out preference signal need not post it at all.
  • There is no private right of action for a bad privacy policy. Section 1798.150(c) confines the consumer cause of action to a breach of nonencrypted, nonredacted personal information caused by a failure of reasonable security, and says the title cannot serve as the basis for a private right of action under any other law.
  • Disclosing to a vendor triggers five mandatory contract terms under section 1798.100(d). That obligation attaches to the disclosure, not to the size of the vendor.

The Direct Answer

The CCPA reaches a for-profit business doing business in California only if it exceeds $25,000,000 in revenue, buys, sells or shares the personal information of 100,000 or more consumers or households, or draws half its revenue from selling or sharing personal information. Merely collecting customer data is not a threshold.

CCPA Small Business Requirements: The Threshold Question

Read the definition before reading anything else, because it is the whole of the analysis for most small companies.

Civil Code section 1798.140(d)(1) defines a “business” as a for-profit legal entity that collects consumers’ personal information, or on whose behalf it is collected, that alone or jointly with others “determines the purposes and means of the processing,” that does business in California, and that satisfies one or more of the following thresholds:

Threshold The statutory text
Revenue “annual gross revenues in excess of twenty-five million dollars ($25,000,000) in the preceding calendar year,” measured as of January 1 of the current year, “as adjusted pursuant to subdivision (d) of Section 1798.199.95”
Volume “Alone or in combination, annually buys, sells, or shares the personal information of 100,000 or more consumers or households”
Business model “Derives 50 percent or more of its annual revenues from selling or sharing consumers’ personal information”

Notice what is absent. There is no threshold based on how many consumers a business collects information from. The volume test counts buying, selling and sharing. A California company with 20,000 customers, an ordinary customer database, no data sales and revenue well under the ceiling meets none of the three, and is not a “business” under this title.

Three extensions widen the net without changing that analysis. Subdivision (d)(2) pulls in an affiliate that shares common branding with a covered business and receives consumers’ personal information from it, where “control” means more than 50 percent of voting securities, control over the election of a majority of directors, or “the power to exercise a controlling influence over the management of a company.” Subdivision (d)(3) treats a joint venture or partnership in which each business holds at least a 40 percent interest as a business, and each constituent business as a separate one. And subdivision (d)(4) allows an entity that is not covered to volunteer – by certifying to the California Privacy Protection Agency that it complies with and agrees to be bound by the title.

Two cautions before anyone concludes they are finished. First, this article is scoped to the CCPA as amended by the CPRA. Other California privacy statutes were not read for it, and being outside the CCPA does not mean a business has no privacy obligations – it means these obligations do not attach. Second, on the ccpa applicability threshold itself, see the next point, because the figure in the Code is not the operative figure.

The Dollar Figures Are Indexed, and They Are Not Published in the Code

This is the part that makes most CCPA articles quietly out of date, including any that quotes $25,000,000 as a fixed number.

Civil Code section 1798.199.95(d)(1) provides that “On January 1, 2025, and on January 1 of any odd-numbered year thereafter, the California Privacy Protection Agency shall adjust the monetary thresholds in” the revenue threshold, the statutory damages provision, the administrative fine provision and two further sections “to reflect any increase in the Consumer Price Index.”

The mechanics are specified. Subdivision (d)(2) requires the agency to use the Consumer Price Index for California, All Items, All Urban Consumers, applying “the percentage change in the CPI for the August-to-August point in time of the prior two years,” rounded to the nearest whole dollar. Subdivision (d)(3) requires the agency to “post the adjusted monetary thresholds on its internet website no later than January 15 of the year in which the adjustment becomes effective.” And subdivision (d)(4) provides that these adjustments and their publication “are not subject to the rulemaking provisions of the Administrative Procedure Act.”

So the current figures are on the agency’s website and nowhere in the statute. This article states the statutory baseline figures because those are what the Code says, and it deliberately does not state a current adjusted figure. Anyone testing a borderline revenue threshold should get the number from the agency rather than from an article – and a business sitting close to the line should re-check it every odd-numbered January.

What Must a Compliant Privacy Policy Disclose?
What Must a Compliant Privacy Policy Disclose?

Three things at or before the point of collection, and the third is the one most policies are missing.

Section 1798.100(a) requires a business that controls the collection of personal information to inform consumers of:

  1. The categories of personal information collected and the purposes for which each category is collected or used, and whether that information is sold or shared. Collecting additional categories, or using information for additional purposes “that are incompatible with the disclosed purpose,” requires fresh notice.
  2. The same for sensitive personal information – categories, purposes, and whether sold or shared.
  3. The length of time the business intends to retain each category of personal information, or the criteria used to determine that period. And a substantive limit rides along with it: a business “shall not retain a consumer’s personal information … for longer than is reasonably necessary for that disclosed purpose.”

That retention disclosure is a CPRA addition, and it is not satisfied by a sentence saying data is kept “as long as necessary.” The statute asks for a period per category, or the criteria used to set one.

Subdivision (c) then imposes data minimization on the practice rather than the policy: collection, use, retention and sharing “shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected.” Subdivision (e) requires reasonable security procedures appropriate to the nature of the information, in accordance with Civil Code section 1798.81.5 – the duty that the private right of action attaches to. Subdivision (f) confirms that nothing in the section requires disclosure of trade secrets.

For california privacy policy requirements under this title, that is the list. Where the reach of the title is in doubt, note again that the definition above decides it.

What Consumer Rights Requests Must a Business Handle?

Requests to know, delete and correct, on a 45-day clock, through at least two channels – with a specific exemption for online-only businesses.

Section 1798.130(a)(1)(A) requires “two or more designated methods for submitting requests … including, at a minimum, a toll-free telephone number.” Then the relief: “A business that operates exclusively online and has a direct relationship with a consumer from whom it collects personal information shall only be required to provide an email address.” Subdivision (a)(1)(B) adds that a business maintaining a website must make the website available for submitting requests.

The timing rules are in subdivision (a)(2)(A):

  • Respond, correct or delete within 45 days of receiving a verifiable consumer request.
  • Determining whether the request is verifiable does not extend that period. The statute says so expressly.
  • The period may be extended once, by a further 45 days, “when reasonably necessary,” provided the consumer is given notice of the extension within the first 45-day period.
  • Disclosure must be in writing, delivered through the consumer’s account if they have one, otherwise by mail or electronically at the consumer’s option, “in a readily useable format that allows the consumer to transmit this information from one entity to another.”

Subdivision (a)(2)(B) sets the lookback: the disclosure covers “the 12-month period preceding the business’ receipt of the verifiable consumer request.” A consumer may request information beyond 12 months once the agency adopts a regulation permitting it, and the business must provide it “unless doing so proves impossible or would involve a disproportionate effort” – but that longer right “shall only apply to personal information collected on or after January 1, 2022.”

The Website Links, and Who Actually Needs Them

Fewer businesses than the internet suggests.

Section 1798.135(a) opens with a condition, not a command. It applies to “a business that sells or shares consumers’ personal information or uses or discloses consumers’ sensitive personal information for purposes other than those authorized by subdivision (a) of Section 1798.121.” A business inside that description must provide, in a reasonably accessible form:

  • a clear and conspicuous homepage link titled “Do Not Sell or Share My Personal Information,” leading to a page that lets a consumer opt out of the sale or sharing of their personal information;
  • a clear and conspicuous homepage link titled “Limit the Use of My Sensitive Personal Information”;
  • or, at the business’s discretion, a single clearly labeled link in lieu of both, if it easily allows the consumer to do both.

And subdivision (b)(1) supplies an alternative to all of it. A business “shall not be required to comply with subdivision (a)” if it allows consumers to opt out and to limit sensitive-information use “through an opt-out preference signal sent with the consumer’s consent” by a platform or mechanism meeting the agency’s technical specifications. A business may then offer a page letting a consumer consent to the signal being ignored, subject to three conditions including that revocation be as easy as consent.

The section closes with a rule worth quoting: “Any provision of a contract or agreement of any kind that purports to waive or limit in any way this subdivision shall be void and unenforceable.”

So a business that does not sell or share, and does not use sensitive personal information beyond the authorized purposes, is not required by this section to post either link. Posting one anyway is a business decision, not compliance.

What Contract Terms Are Required With Vendors and Service Providers?
What Contract Terms Are Required With Vendors and Service Providers?

Five, and they attach to the disclosure rather than to the size of anyone involved.

Section 1798.100(d) provides that a business that sells personal information to, shares it with, a third party, or discloses it to a service provider or contractor for a business purpose “shall enter into an agreement” with that recipient which:

  1. Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.
  2. Obligates the recipient to comply with the title and to “provide the same level of privacy protection as is required by this title.”
  3. Grants the business rights to take reasonable and appropriate steps to help ensure the recipient uses the information consistently with the business’s own obligations.
  4. Requires the recipient to notify the business if it determines that it can no longer meet its obligations under the title.
  5. Grants the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use.

For a cpra compliance checklist, this is the item most often skipped, because it is not a website task. It is a paper task across every payroll processor, email platform, analytics provider, CRM and outsourced support desk that receives customer data – and it is the business’s obligation to have the agreement, not the vendor’s.

What Are the Penalties for Noncompliance?

Two separate exposures, and the smaller one is the one most articles overstate.

Administrative fines. Section 1798.155(a) makes a business, service provider, contractor or other person that violates the title liable for an administrative fine of up to $2,500 per violation, or $7,500 for each intentional violation, in each case the amount as of drafting or one involving a consumer the business knows is under 16, as adjusted under the indexing provision, “in an administrative enforcement action brought by the California Privacy Protection Agency.”

The section as read contains no cure period. Anyone relying on a 30-day right to fix an administrative violation should not; that right does not appear in this section.

Private actions, and only for breaches. Section 1798.150(a)(1) gives a consumer a civil action where nonencrypted, nonredacted personal information, or an email address combined with a password or security question and answer permitting account access, is subject to unauthorized access and exfiltration, theft, or disclosure because the business failed to maintain reasonable security procedures. Statutory damages run from $100 to $750 per consumer per incident – statutory figures as of drafting – or actual damages, whichever is greater, adjusted under the indexing provision. Subdivision (a)(2) lists what the court weighs, including the persistence and willfulness of the misconduct and the defendant’s assets, liabilities and net worth.

Two features of that action matter to a small business. Subdivision (b) requires the consumer to give 30 days’ written notice identifying the specific provisions before suing for statutory damages, and a genuine cure plus an express written statement within that window bars statutory damages – except that “the implementation and maintenance of reasonable security procedures and practices … following a breach does not constitute a cure with respect to that breach.” Fixing the security afterwards does not undo the exposure.

And subdivision (c) is the limit: the cause of action “shall apply only to violations as defined in subdivision (a) and shall not be based on violations of any other section of this title,” and “Nothing in this title shall be interpreted to serve as the basis for a private right of action under any other law.” A deficient privacy policy, a missed rights request or an absent opt-out link is an agency matter, not a lawsuit.

When to Bring Counsel In

At the threshold, and at the vendor list.

The threshold is worth getting right once rather than assuming either way, because the consequences of both errors are real: a business that is covered and behaves as though it is not accrues per-violation exposure, and a business that is not covered but adopts a full compliance program spends money on obligations it does not have. The indexed revenue figure makes this a recurring question rather than a one-time one for any company near the line.

The vendor list is the second moment, because section 1798.100(d)’s five terms have to be in agreements that already exist, which usually means amendments rather than drafting. And the third is the day of a suspected breach, because the private action turns on reasonable security and the statute is explicit that improving security afterwards is not a cure.

Adjacent questions are covered separately: what the statement of information requires, whether the business needs a local business license, what compliance looks like for a regulated California business, and which contracts a small business should have in place.

Work with Bay Legal

Bay Legal, PC advises California businesses on CCPA applicability, privacy policy and notice-at-collection drafting, consumer rights request procedures, and the vendor and service provider agreement terms the statute requires. If you are unsure whether the Act reaches you, or a rights request or a breach has arrived, call (650) 668-8000 in Northern California or (213) 668-8000 in Southern California, or schedule a consultation at https://baylegal.com/contact-us/.

Frequently Asked Questions

Does the CCPA apply to my small California business?

Only if it meets one of three thresholds in Civil Code section 1798.140(d)(1): annual gross revenues over $25,000,000 in the preceding calendar year, buying, selling or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenues from selling or sharing personal information. There is no threshold for merely collecting information, so an ordinary customer database does not bring a small company inside the Act. Affiliates under common branding, and joint ventures where each party holds 40 percent, are also covered.

What must a compliant privacy policy disclose?

Under section 1798.100(a), at or before the point of collection: the categories of personal information collected and the purposes, and whether it is sold or shared; the same for sensitive personal information; and the length of time the business intends to retain each category, or the criteria used to determine that period. The retention item is a CPRA addition and is not satisfied by saying data is kept as long as necessary. Subdivision (c) separately limits collection, use, retention and sharing to what is reasonably necessary and proportionate.

What consumer rights requests must a business handle?

Requests to know, delete and correct, through at least two designated methods including a toll-free number – except that a business operating exclusively online with a direct consumer relationship need only provide an email address. Section 1798.130(a)(2)(A) requires a response within 45 days of a verifiable request, extendable once by a further 45 days with notice inside the first period, and verifying the request does not extend the clock. The disclosure covers the 12 months preceding receipt.

What contract terms are required with vendors and service providers?

Five, under section 1798.100(d). The agreement must specify that information is sold or disclosed only for limited and specified purposes; obligate the recipient to comply with the title and provide the same level of privacy protection it requires; grant the business rights to take reasonable steps to ensure consistent use; require the recipient to notify the business if it can no longer meet its obligations; and grant the business the right, on notice, to stop and remediate unauthorized use. The duty attaches to the disclosure, not to the vendor’s size.

What are the penalties for noncompliance?

Administrative fines under section 1798.155(a) of up to $2,500 per violation, or $7,500 for an intentional violation or one involving a consumer the business knows is under 16, as indexed, in an action brought by the California Privacy Protection Agency – and the section contains no cure period. Separately, section 1798.150 gives consumers a private action only for a breach of nonencrypted, nonredacted personal information caused by a failure of reasonable security, with statutory damages of $100 to $750 per consumer per incident.

Disclaimer: This article is for general informational purposes only and is not legal, tax, or financial advice. Reading it or contacting Bay Legal, PC does not create an attorney-client relationship. It addresses California law only; other states differ. The law changes, and figures and procedures described here may be updated after this article’s publication date.

BOOK A CONSULTATION

Latest Legal Blogs

Hear From Our Clients