Veracly
Multi-jurisdiction

When does a small business lose its compliance carve-outs?

GDPR has no small-business exemption. EAA has one but only for service providers. CCPA kicks in at $25M revenue or 100k consumers. Each regulation draws the line differently, here is the map.

By Veracly Compliance Team7 min read

Every regulator that has thought about small business has answered “at what size do you apply?” differently. The result for an SMB owner: a patchwork of thresholds, each measured against a different metric, each triggering a different obligation. Here is the actual map.

GDPR, no threshold

Regulation (EU) 2016/679 applies to any organization established in the EU that processes personal data, regardless of size. It also reaches organizations with no EU establishment, but only on the Article 3(2) conditions: offering goods or services to data subjects in the Union, or monitoring their behaviour in the Union. Note the wording. The test is where the data subject is, not their residence or citizenship, and merely being reachable from the EU is not enough. The EDPB Guidelines 3/2018 look for evidence of targeting, EU currencies, EU languages, EU-specific delivery, EU-directed marketing. A one-person consultancy that happened to take one EU customer without ever aiming at the EU market is probably outside Article 3(2); the same consultancy running EU-targeted ads is squarely inside it. Either way there is no size threshold.

The single SME-friendly carve-out is Article 30(5): organizations under 250 employees are exempt from maintaining records of processing activities, except when processing is not occasional, includes special categories (health, race, religion, etc.), or is likely to result in risk to data subjects. Most SMBs process customer data continuously, which means “not occasional,” which means the carve-out does not actually apply. Treat as if Article 30 applies in full.

ePrivacy Directive, no threshold

Directive 2002/58/EC and its national transpositions apply to any electronic communications service or website operating in the EU. No size carve-out. A solo developer’s blog has the same cookie-consent obligations as a 10,000-employee enterprise.

EU Accessibility Act, microenterprise exemption for services only

Directive (EU) 2019/882 Article 4(5) exempts microenterprises providing services from the EAA service obligations. The test sits in Article 3(23), and its shape matters: fewer than 10 persons employed and either an annual turnover not exceeding €2M or an annual balance-sheet total not exceeding €2M. The headcount limb is mandatory; the financial limb is a disjunction, so a 9-person firm with €3M turnover and a €1M balance-sheet total is still a microenterprise. The exemption does not extend to:

  • EAA-covered products (manufacturers, importers, distributors).
  • Antidiscrimination law (UK Equality Act, German AGG, French 2005 law), which carries no size threshold of its own.

A common misreading is that national accessibility law claws the exemption back. It usually does not. Germany’s BFSG is the German transposition of the EAA, not a pre-existing parallel regime, and § 3 Abs. 3 BFSG carries the identical microenterprise carve-out for service providers. France’s RGAA duty, under art. 47 of the 2005 law, starts at €250 million turnover, which is far above any SMB. Neither bites below the EAA threshold. Check the transposing statute in each member state you actually sell into rather than assuming a stricter local floor exists.

See our detailed write-up on the EAA exemption.

UK Equality Act 2010, no threshold for reasonable adjustments

The reasonable-adjustments duty under Section 20 applies to every service provider regardless of size. The duty is anticipatory, a 2-person service provider must consider accessibility before being asked. The Equality and Human Rights Commission (EHRC) has been consistent that resource constraints affect the “reasonable” qualifier but not the existence of the duty.

US ADA Title III, “public accommodations”

The ADA does not use a head-count threshold. Title III applies to any business qualifying as a “public accommodation”, a category covering retail, restaurants, professional services, lodging, transportation, education, and recreation. Most SMB websites qualify; corporate B2B websites with no consumer interface generally do not.

Title I (employment) has a 15-employee threshold but does not regulate websites. The DOJ’s April 2024 final rule under Title II applies to state and local government, not private SMBs.

California CCPA / CPRA, three thresholds, any one triggers

California Civil Code §1798.140(d) defines a covered business as a for-profit entity that:

  • Has annual gross revenues over $25 million; or
  • Buys, sells, shares, or receives personal information of 100,000 or more California consumers or households annually; or
  • Derives 50% or more of annual revenue from selling or sharing personal info.

The three thresholds are independent. An SMB with $5M revenue can still cross the 100,000-consumers bar if they run a high-traffic California-facing site. Once covered, the full CCPA/CPRA suite applies.

Colorado, Connecticut, Texas, Virginia, Utah, converging

The post-CCPA wave of US state privacy laws settled on a similar pattern: revenue or volume-based thresholds, focused on consumer-data sales. The current population of state laws (2026):

  • Colorado, Connecticut: 100,000 consumers per year, or 25,000 consumers + revenue from sales.
  • Virginia: 100,000 consumers, or 25,000 + 50% sale revenue.
  • Utah: $25M revenue + 100,000 consumers OR 25,000 + 50% sale revenue.
  • Texas TDPSA: “Conducts business in Texas” with no size threshold, but the substantive duties only apply to non-small-businesses (under SBA size standard).
  • Other states (DE, MD, OR, MN, NJ, NH, KY, etc.): similar 100k consumer / 25k+sale-revenue pattern, with some variation.

Australian Privacy Act, AUD 3M threshold

The Privacy Act 1988 applies to organizations with annual turnover above AUD 3 million. Below that, organizations are exempt from the Australian Privacy Principles (APPs) entirely. Exceptions:

  • Health service providers (no threshold, covered regardless).
  • Organizations that trade in personal information.
  • Contractors to the federal government.
  • Credit reporting bodies, residential tenancy databases.

The AUD 3M threshold is under reform; the Australian government has signaled intent to lower it substantially. The 2024 reform package proposes phased extension to all organizations regardless of turnover, with smaller-business obligations tiered. Plan as if the threshold may be lowered in 2026 to 2027.

Canada, PIPEDA + provincial

PIPEDA applies federally to commercial activities; no size threshold. Provincial laws (Quebec Law 25, BC PIPA, Alberta PIPA) apply additionally; Quebec’s Law 25 is the strictest and applies to any organization processing Quebec residents’ data, no size carve-out.

AODA (Ontario) applies to every Ontario organization with at least one employee. The 50-employee line people quote gates exactly one duty: IASR s. 14, the obligation to make websites and web content conform to WCAG 2.0 Level AA (and note that s. 14 also carves out live captioning and audio description). An organization with 1 to 49 employees still owes the customer service standard, accessibility policies, staff training, and accessible formats and communication supports on request. “Under 50, nothing applies” is the single most common AODA error.

Brazil LGPD, no threshold

Lei Geral de Proteção de Dados (LGPD) applies to any organization processing data of Brazilian residents, no size carve-out. Penalty caps are smaller for small-and-startup organizations under ANPD regulation (RDA 4 of 2023), but the substantive obligations apply equally.

The compounding effect

An SMB selling EU + UK + US + Canadian customers is simultaneously under: GDPR (no threshold), ePrivacy (no threshold), UK Equality Act (no threshold), ADA (public accommodation), and possibly CCPA + Colorado + Texas + Quebec Law 25. Each has its own consent regime, breach notification timeline, data subject rights, and enforcement body.

This compounding is why “we are small, we are exempt” is rarely accurate for an SMB with cross-border traffic. The exemptions stack, qualifying for one is not the same as qualifying for all, and the substantive obligations of the regulations without size thresholds (GDPR, ePrivacy, UK Equality Act, ADA, Quebec Law 25, LGPD) cover most of the surface anyway.

What Veracly does, and does not, track for you

Veracly does not ask you to declare a size band, and there is no size field anywhere in the product. That is deliberate. Severity is fixed per rule pack, so an EAA finding is graded identically whether you have four employees or four hundred. We are not willing to downgrade a finding to “informational” on the strength of a self-declared headcount, because that declaration is exactly the thing a regulator would test first, and a report that softened its own findings on an untested input would be worth nothing when it mattered.

What the scan does select on is jurisdiction. Rule-pack selection is driven by the country inferred for the site and the visitor countries configured on your plan, so a site with no EEA footprint in scope is not graded against the EAA at all. Whether the microenterprise exemption applies to you is a legal question about headcount, turnover, and whether you are a service provider or a manufacturer, and the report does not answer it. The Methodology section is a short note on how the scan works, crawling, axe-core, network interception, policy pages, not a threshold analysis. Use this page for the thresholds, then check the transposing statute for your market.

See also: EAA microenterprise exemption · Multi-jurisdiction website compliance

Common questions

Does GDPR have a small-business exemption?+

No. GDPR Article 30 has a partial exemption from the "records of processing activities" obligation for organizations under 250 employees, but that is a paperwork carve-out, not a substantive one. All other GDPR obligations, lawful basis, consent, data subject rights, breach notification, transfers, apply regardless of size.

What is the most common threshold across all regulations?+

There is no single one. The closest to a common threshold is the EU SME definition (<50 employees, <€10M turnover) and the EU microenterprise definition. Note that the microenterprise test is not a flat conjunction: EAA Article 3(23) requires fewer than 10 persons employed AND either turnover not exceeding €2M OR a balance-sheet total not exceeding €2M, so the financial limb is an either/or. The substantive regulations (GDPR, ePrivacy, EAA, ADA, CCPA) each pick their own bar anyway.

When does my US site come under CCPA?+

When you cross any of: $25M annual revenue, buying/selling/sharing personal info of 100,000 California consumers or households, or deriving 50%+ of revenue from selling/sharing personal info. The thresholds are independent, meeting one is enough.

See where your site stands.

Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.

Run a free scan

Keep reading