Privacy Laws With No Revenue Threshold: Which Laws Apply to Every Business?

Overview of privacy laws with no size exemption, including GDPR, UK GDPR, Quebec Law 25, and POPIA. Why small businesses cannot assume exemption.

Last updated: 2026-08-16

Size Does Not Buy You an Exemption

Many small business owners assume privacy laws only apply to large corporations. This assumption is wrong and increasingly dangerous. Several major privacy laws around the world apply regardless of a company's revenue, headcount, or size. If you process personal data, you may be subject to these laws whether you are a multinational enterprise or a sole trader.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. Consult a qualified attorney for guidance specific to your business. The information here reflects the laws discussed as of the date of publication.

This guide covers which privacy laws have no revenue threshold, which use processing-based rather than size-based applicability tests, and what small businesses should be doing to comply.

Privacy Laws With No Revenue or Size Threshold

The following laws apply to organizations regardless of their annual revenue or number of employees. The determining factor is whether you process personal data, not how big your business is.

GDPR (European Union)

The General Data Protection Regulation applies to any organization that processes the personal data of individuals in the European Economic Area, regardless of the organization's size or revenue. There is no small business exemption.

A freelancer in Berlin with 50 clients has the same legal obligations as a company with 50 million customers. The practical scope of those obligations scales — a sole trader does not need a full-time DPO — but the law applies equally.

GDPR Article 30(5) offers a limited exemption from record-keeping requirements for organizations with fewer than 250 employees, but only if processing is not likely to result in a risk to rights and freedoms, is not occasional, and does not include special categories of data. In practice, most businesses processing customer data on a regular basis do not qualify for this narrow exemption.

For a full overview of GDPR requirements, see our GDPR jurisdiction guide.

UK GDPR (United Kingdom)

The UK GDPR mirrors the EU GDPR in its scope. It applies to all organizations processing personal data of individuals in the UK, with no revenue or size threshold. The same Article 30(5) record-keeping exemption exists and is equally narrow.

The ICO has consistently emphasized that small businesses are not exempt. Their guidance materials include specific resources for small and micro organizations, acknowledging that the law applies to them while recognizing that compliance efforts should be proportionate.

See our UK GDPR jurisdiction guide for UK-specific requirements.

Quebec Law 25 (Canada)

Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25 (formerly Bill 64), applies to every private-sector organization that collects, holds, uses, or communicates personal information in Quebec. There is no revenue threshold and no size-based exemption.

The law's final provisions took effect on September 22, 2024, and every business in Quebec must comply — including requirements for privacy policies, breach notification, privacy impact assessments, and responding to access requests within 30 days.

New Zealand Privacy Act 2020

New Zealand's Privacy Act applies to every "agency" that holds personal information, which includes nearly all private-sector organizations. There is no turnover threshold or employee count requirement. The law applies equally to a one-person consultancy and a nationwide retailer.

POPIA (South Africa)

South Africa's Protection of Personal Information Act applies to all responsible parties who process personal information, with no revenue or size exemption. The Information Regulator enforces compliance and has been active since July 2021, when the enforcement provisions took effect.

LGPD (Brazil)

Brazil's Lei Geral de Protecao de Dados applies to any organization that processes personal data collected in Brazil or that offers goods or services to individuals in Brazil. While the ANPD (Brazil's data protection authority) has issued simplified compliance guidance for small businesses and startups, the law itself applies to all organizations. The simplified provisions reduce administrative burden but do not eliminate substantive obligations.

PDPL (Saudi Arabia)

Saudi Arabia's Personal Data Protection Law, which took effect in September 2023 with a compliance grace period, applies to any processing of personal data within Saudi Arabia or personal data of Saudi residents. There is no size-based exemption.

US Privacy Laws: Processing Thresholds, Not Revenue Alone

The United States takes a different approach. Rather than applying privacy laws universally, most US state privacy laws use applicability thresholds based on a combination of revenue and data processing volume. However, some states set thresholds that capture businesses well below what most people would consider "large."

States With Revenue Thresholds

The California Consumer Privacy Act (CCPA), as amended by the CPRA, applies to for-profit businesses that meet any one of three tests: annual gross revenue exceeding $25 million, buying/selling/sharing the personal information of 100,000 or more consumers or households annually, or deriving 50% or more of annual revenue from selling or sharing personal information. Small businesses below all three thresholds are generally exempt.

Several other state laws use similar approaches. Virginia's CDPA, Colorado's CPA, and Connecticut's CTDPA all set processing volume thresholds (typically 100,000 consumers or 25,000 consumers combined with revenue from data sales) but do not set minimum revenue thresholds. This means a small company that processes large volumes of consumer data — such as a mobile app developer or an ad-tech startup — can be covered even with modest revenue.

States With Lower Bars

Some newer state privacy laws set thresholds that pull in smaller businesses:

  • Montana's Consumer Data Privacy Act applies to businesses that process personal data of 50,000 consumers (the lowest threshold among US states as of mid-2026).
  • New Hampshire, New Jersey, Delaware, and Nebraska have thresholds at or around 35,000 to 100,000 consumers for businesses not meeting the revenue-from-sale test.

The trend in US state legislation is toward lower thresholds, meaning more businesses will be covered over time.

The Federal Landscape

As of mid-2026, the United States does not have a comprehensive federal privacy law. The American Data Privacy and Protection Act (ADPPA) was proposed but not enacted. Federal requirements remain sector-specific: HIPAA for health data, GLBA for financial data, COPPA for children's data, and FERPA for educational records. These sector-specific laws have their own applicability tests.

Why Small Businesses Cannot Assume Exemption

Even if your business might fall below a particular threshold, there are several reasons you should not assume you are exempt:

Extraterritorial reach. The GDPR applies to any business that processes data of individuals in the EEA, regardless of where the business is located. If you have a single customer in France, the GDPR may apply to you. The same is true for the UK GDPR, Brazil's LGPD, and several other laws. You do not need to be physically present in a jurisdiction to be subject to its privacy law.

Threshold calculations are tricky. Under CCPA, the 100,000 consumer threshold includes households and devices, not just named individuals. A small e-commerce site with moderate traffic may hit this number faster than expected, particularly if it uses cookies or tracking technologies that create records tied to individual devices or IP addresses.

Laws change. Thresholds tend to decrease over time, not increase. A business that is exempt today may not be exempt next year. Building a basic privacy compliance program now is easier and cheaper than scrambling to comply under pressure.

Customer expectations. Regardless of legal requirements, customers increasingly expect businesses of all sizes to handle their data responsibly. Receiving an access or deletion request and responding with "we are not legally required to comply" is technically possible in some cases, but it damages trust and risks negative attention.

Contractual obligations. Even if no privacy law directly applies to your business, your contracts with larger companies may require you to comply. Many enterprise customers and platforms require their vendors and partners to meet specific privacy standards regardless of the vendor's size.

Quick Compliance Checklist for Small Businesses

If you process personal data — and if you have customers, employees, or website visitors, you do — here is a baseline checklist that satisfies the core requirements of most privacy laws:

1. Know what data you collect and where it is stored. Create a basic data inventory. List your systems, what personal data each holds, and how long you keep it. See our guide on data mapping for DSAR readiness.

2. Have a privacy policy. Publish a clear, accurate privacy policy that explains what data you collect, why you collect it, who you share it with, and how individuals can exercise their rights. This is required under virtually every privacy law.

3. Establish a process for access and deletion requests. You need a way to receive, process, and respond to requests from individuals about their data. It does not need to be automated — a documented manual process is fine for low volumes. See our DSAR workflow guide.

4. Implement reasonable security. Protect the personal data you hold with appropriate technical and organizational measures. Strong passwords, encryption in transit, access controls, and regular software updates are the basics.

5. Have a breach response plan. Know what you will do if personal data is compromised. Under many laws, you must notify the relevant authority and affected individuals within defined timeframes.

6. Manage consent properly. Where consent is the legal basis for processing (as opposed to contract performance, legal obligation, or legitimate interests), make sure it is freely given, specific, informed, and unambiguous. Under GDPR, pre-ticked boxes do not count.

7. Review your vendors. If you share personal data with third-party service providers, make sure appropriate data processing agreements are in place and that those providers meet adequate security standards.

The Cost of Getting It Wrong

Enforcement is not limited to large companies. The GDPR has been enforced against small businesses, individual practitioners, and sole traders. The ICO in the UK has issued fines and enforcement notices to small organizations. South Africa's Information Regulator has acted against businesses of various sizes.

The penalties for non-compliance can be severe relative to a small business's resources. Under GDPR, fines can reach 4% of annual worldwide turnover or 20 million euros, whichever is higher. For a small business, even a fine at the lower end of the scale can be existential.

Beyond fines, regulatory investigations consume time and management attention. Responding to a regulator's inquiry is far more expensive and stressful than building a basic compliance program in the first place.

Related Guides

References

  • GDPR: Article 30(5) — record-keeping exemption. GDPR Article 30
  • Quebec Law 25: Commission d'acces a l'information du Quebec. CAI guidance
  • CCPA: Cal. Civ. Code § 1798.140(d) — definition of "business" and applicability thresholds. CCPA text
  • POPIA: Protection of Personal Information Act 4 of 2013. POPIA text
  • NZ Privacy Act 2020: Office of the Privacy Commissioner New Zealand. OPC NZ

Last reviewed: August 2026. Privacy laws change frequently. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.