CCPA/CPRA consumer rights framework — enumerated rights and response timeline
The California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA, Proposition 24), grants California consumers a statutory bundle of privacy rights against businesses that collect their personal information. The CPRA amendments became operative January 1, 2023. The California Privacy Protection Agency (CPPA) holds full administrative power to implement and enforce the statute.
Enumerated consumer rights
California residents ("consumers" under the statute) have the following rights with respect to their personal information:
- Right to know (Cal. Civ. Code §§ 1798.100, 1798.110) — the right to request that a business disclose the categories and specific pieces of personal information it has collected about the consumer, the categories of sources, the business or commercial purpose for collection, and the categories of third parties to whom the business discloses personal information.
- Right to delete (Cal. Civ. Code § 1798.105) — the right to request that a business delete any personal information about the consumer that the business has collected from or about the consumer, subject to enumerated exceptions (security, fraud detection, legal compliance, free speech, research, and internal uses that the consumer would reasonably expect).
- Right to correct (Cal. Civ. Code § 1798.106) — the right to request that a business correct inaccurate personal information that it maintains about the consumer.
- Right to opt out of sale or sharing (Cal. Civ. Code § 1798.120) — the right to direct a business that sells or shares the consumer's personal information to third parties to stop doing so. "Sale" is defined broadly to include disclosing personal information to a third party for monetary or other valuable consideration (§ 1798.140(ad)); "sharing" means disclosing personal information to a third party for cross-context behavioral advertising (§ 1798.140(ah)).
- Right to limit use and disclosure of sensitive personal information (Cal. Civ. Code § 1798.121) — the right to direct a business that uses or discloses sensitive personal information for purposes beyond those necessary to perform services reasonably expected by the consumer to limit that use. Sensitive personal information includes Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, mail/email/text content, genetic data, biometric data processed for unique identification, health data, sex life or sexual orientation data, and (as of January 1, 2025) neural data.
- Right to non-discrimination (Cal. Civ. Code § 1798.125) — the right not to receive discriminatory treatment (denial of goods or services, different pricing, different quality of service) for exercising CCPA rights. A business may offer financial incentives or different prices if the difference is reasonably related to the value provided to the business by the consumer's data.
Response timeline and verification
A business that receives a verifiable consumer request must respond within 45 days of receipt (Cal. Civ. Code § 1798.130(a)(2); CPPA regulations § 7000 et seq.). The 45-day period may be extended once by an additional 45 days (for a maximum 90 days total) when reasonably necessary, taking into account the complexity and number of requests, provided the business informs the consumer of the extension within the initial 45-day period and provides the reasons for the delay.
The business must disclose and deliver the required information free of charge. Information may be delivered electronically or by mail; if electronic, it must be portable and in a readily usable format that allows the consumer to transmit the information to another entity without hindrance.
A business is not obligated to provide information pursuant to the right-to-know provisions (§§ 1798.110, 1798.115) to the same consumer more than twice in a 12-month period.
The business may deny a request if it cannot verify that the consumer making the request is the consumer about whom the business has collected information, pursuant to verification standards set forth in CPPA regulations. If the business does not take action on a consumer request, it must inform the consumer of the reasons for not taking action and any rights the consumer may have to appeal the decision, within the applicable response period.
Source: Cal. Civ. Code §§ 1798.100–1798.130 Source: CPPA FAQ — Consumer Rights
Verification standards for consumer requests — risk-tiered thresholds and data minimization
Businesses must verify the identity of consumers submitting requests to know, delete, or correct personal information before disclosing data or taking action. The CCPA imposes a risk-tiered verification framework that calibrates the degree of certainty required to the sensitivity of the information at issue and the potential harm posed by unauthorized access or deletion. The California Privacy Protection Agency (CPPA) regulations at 11 CCR §§ 7060–7062 implement Cal. Civ. Code § 1798.130(a)(2) and mandate data minimization: businesses must first attempt to verify the consumer using information already maintained, and may request additional information only if verification cannot be completed with existing data.
Two-tier verification standard — § 7060(c)
The CPPA regulations prescribe different verification thresholds depending on the nature of the request:
- Reasonable degree of certainty — required for requests to know categories of personal information (e.g., "what types of data do you collect about me?"). A business must match the information provided in the request with information already maintained about the consumer to a reasonable degree of certainty. 11 CCR § 7060(c)(1).
- Reasonably high degree of certainty — required for requests to know specific pieces of personal information (e.g., "provide me a copy of my purchase history") and requests to delete or correct. A business must match the request to existing information to a reasonably high degree of certainty. 11 CCR § 7060(c)(2), (c)(3). This heightened standard reflects the greater risk of harm from unauthorized disclosure of individualized data or from unauthorized deletion.
The regulations do not quantify "reasonable" or "reasonably high" in numerical terms. CPPA Enforcement Advisory 2024-01 (April 2, 2024) instructs businesses to evaluate the sensitivity of the information, the risk of harm from unauthorized access or deletion, and whether the business can rely on information already on file (such as an email address from which the request originates) or whether additional verification steps—such as requesting a driver's license number or using multi-factor authentication—are proportionate to the risk.
Password-protected accounts — § 7061
For consumers who maintain a password-protected account with the business, verification is simpler. A business may verify a consumer request by requiring the consumer to submit the request through the consumer's existing account. 11 CCR § 7061(a). If the business has an existing process to authenticate account holders at login (e.g., username/password, two-factor authentication), that process satisfies verification for all request types if the consumer is logged in at the time of the request.
A business may not require a consumer to create an account solely to submit a verifiable consumer request. Cal. Civ. Code § 1798.130(a)(2)(B).
Non-accountholders — § 7062
For consumers without password-protected accounts, the business must verify the consumer by matching data points provided in the request against information the business already maintains. 11 CCR § 7062(a). The regulation sets out request-specific guidance:
- Requests to know categories (§ 7062(b)): A business may request that the consumer provide two data points that the business already maintains (e.g., name and email address). If the business can verify the consumer to a reasonable degree of certainty using one data point (e.g., a unique email from which the request was sent), it may not demand additional information.
- Requests to know specific pieces or requests to correct (§ 7062(c)): A business may request that the consumer provide at least three pieces of personal information that the business already maintains and that the business matches against its records to a reasonably high degree of certainty. The business must also implement reasonable security measures to ensure that the person making the request is the consumer about whom the business has collected information.
- Requests to delete (§ 7062(d)): A business may require the consumer to provide information that the business matches to a reasonably high degree of certainty, and may require a signed declaration under penalty of perjury that the requestor is the consumer whose information is subject to the request. The business may also require the consumer to confirm separately that they want to proceed with deletion (a "double opt-in" mechanism to guard against accidental or fraudulent deletions).
Data minimization — § 7002(d) and § 7060(d)
Cal. Civ. Code § 1798.100(c) requires businesses to collect, use, retain, and share personal information only to the extent "reasonably necessary and proportionate" to achieve the purposes for which the information was collected or processed. This data minimization principle applies to verification. A business must generally avoid requesting additional information from the consumer for purposes of verification. 11 CCR § 7060(d). If the business cannot verify the consumer's identity using information already maintained, it may request additional information, but that new information may be used only for verification, security, or fraud prevention, and must be deleted as soon as practicable after processing the request. 11 CCR § 7060(d); Cal. Civ. Code § 1798.130(a)(2)(C).
CPPA Enforcement Advisory 2024-01 illustrates the principle: if a business holds only a consumer's name and email address, and the consumer submits a deletion request from that email address, the business must evaluate whether it can verify the consumer using the email alone (perhaps with a confirmation link sent to that email) rather than demanding a driver's license number or Social Security number, which would be disproportionate and would introduce new sensitive data that itself creates risk if breached.
No verification required for opt-out requests
A business may not require a consumer to verify their identity in order to submit a request to opt out of sale/sharing (Cal. Civ. Code § 1798.120(c)) or to limit use of sensitive personal information (Cal. Civ. Code § 1798.121(b)). The consumer must be able to exercise these rights through an opt-out preference signal (such as the Global Privacy Control) without providing any additional information. 11 CCR § 7026(c)–(d).
Source: Cal. Civ. Code § 1798.130 Source: Cal. Civ. Code § 1798.100 Source: 11 CCR §§ 7060–7062 (CPPA Regulations, effective March 29, 2023; updated Jan. 1, 2026) Source: CPPA Enforcement Advisory 2024-01 (Data Minimization)
Right to delete — statutory exceptions under Cal. Civ. Code § 1798.105(d)
The CCPA/CPRA right to delete (Cal. Civ. Code § 1798.105(a)) is not absolute. A business, service provider, or contractor shall not be required to comply with a consumer's deletion request if it is reasonably necessary to maintain the consumer's personal information in order to accomplish one of nine enumerated statutory purposes. § 1798.105(d). When a business invokes an exception, it may retain only the specific personal information required for that purpose—the exception does not authorize retention of the consumer's entire data set.
The nine statutory exceptions
Under § 1798.105(d), a business need not delete personal information if retention is reasonably necessary to:
- Complete the transaction, fulfill a warranty or product recall, provide a requested or reasonably anticipated good or service, or perform a contract (§ 1798.105(d)(1)). This exception covers the entire lifecycle of a transaction for which the personal information was collected. It includes fulfilling the terms of a written warranty or a product recall conducted in accordance with federal law, providing a good or service requested by the consumer, providing a good or service reasonably anticipated by the consumer within the context of a business's ongoing business relationship with the consumer, and otherwise performing a contract between the business and the consumer.
- Help ensure security and integrity, to the extent reasonably necessary and proportionate (§ 1798.105(d)(2)). This exception permits retention necessary to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity. The statute adds a proportionality requirement: the use of the consumer's personal information must be "reasonably necessary and proportionate" for the security or integrity purpose. The exception does not specify which types of data qualify, but it is understood to encompass logs and records used to investigate and prevent fraud and abuse.
- Debug to identify and repair errors that impair existing intended functionality (§ 1798.105(d)(3)). This exception applies only to existing functionality—the statute does not extend it to development of new features. A business may retain personal information needed to identify, diagnose, and repair errors, but only for as long as the debugging process requires.
- Exercise free speech, ensure another consumer's right to free speech, or exercise another right provided for by law (§ 1798.105(d)(4)). This exception accommodates First Amendment interests and other legal rights. It has been invoked to justify retention of user-generated content (such as product reviews or public comments) and to comply with legal obligations such as litigation holds or public-records laws. The exception does not define which rights qualify, and it does not grant blanket immunity from deletion—a business must identify a specific legal right.
- Comply with the California Electronic Communications Privacy Act (CalECPA) (§ 1798.105(d)(5)). CalECPA (Cal. Penal Code §§ 1546 et seq.) imposes warrant and court-order requirements on government access to electronic communications and metadata. This exception permits a business to retain personal information if deletion would violate CalECPA—for example, if the business has received a valid court order requiring preservation of specified communications. The statute does not elaborate on other scenarios where this exception applies.
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest (§ 1798.105(d)(6)). This exception applies only when three conditions are met: (a) the research conforms to or adheres to all other applicable ethics and privacy laws; (b) the business's deletion of the information is likely to render impossible or seriously impair the ability to complete such research; and (c) the consumer has provided informed consent. The CCPA defines "research" at Cal. Civ. Code § 1798.140(ag) to require that research be in the public interest and that personal information be deidentified, pseudonymized, or aggregated. The statute does not define "public interest" or specify when commercial research qualifies.
- Enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer's relationship with the business and compatible with the context in which the consumer provided the information (§ 1798.105(d)(7)). This exception protects retention for internal purposes that a consumer would reasonably expect. The statute does not define "internal uses" or provide a list of qualifying purposes. It requires a contextual, fact-specific evaluation of consumer expectations at the time the data was collected.
- Comply with a legal obligation (§ 1798.105(d)(8)). This exception encompasses any federal, state, or local law that requires the business to retain personal information. Examples include tax recordkeeping requirements (IRS and California Franchise Tax Board retention schedules), employment records (Equal Employment Opportunity Commission, Occupational Safety and Health Administration, and wage-and-hour laws), financial-services records (Securities and Exchange Commission, Financial Industry Regulatory Authority, and Gramm-Leach-Bliley Act retention rules), and healthcare records (Health Insurance Portability and Accountability Act and California Health & Safety Code retention rules). The statute does not define "legal obligation," but CPPA guidance confirms it applies when the business is "legally required to keep the information." CPPA FAQ. A business invoking this exception should identify the specific statute, regulation, or court order requiring retention.
- Otherwise use the consumer's personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information (§ 1798.105(d)(9)). This catch-all exception applies to any internal, lawful use compatible with the context in which the consumer provided the information. The statute does not specify how it differs from exception (7); both require contextual compatibility and internal use. Exception (9) does not impose an express "reasonable expectations" test, but compatibility with context necessarily implicates the consumer's understanding of how the data would be used.
"Reasonably necessary" standard
All nine exceptions are conditioned on retention being "reasonably necessary" (or, in the case of exception (2), "reasonably necessary and proportionate"). The statute does not define "reasonably necessary." CPPA regulations impose a data-minimization principle on verification and other CCPA processes, requiring businesses to collect, use, retain, and share personal information only to the extent "reasonably necessary and proportionate" to achieve the stated purposes. 11 CCR § 7002(d); Cal. Civ. Code § 1798.100(c). This principle applies to the exceptions: a business should retain only the minimum personal information required to accomplish the permitted purpose, and only for as long as necessary.
Cascading deletion obligations — § 1798.105(c)
When a business receives a verifiable consumer request to delete, it must (1) delete the consumer's personal information from its own records; (2) notify any service providers or contractors to delete the consumer's personal information from their records; and (3) notify all third parties to whom the business has sold or shared the personal information to delete the consumer's personal information—unless this proves impossible or involves disproportionate effort. § 1798.105(c)(1). The "impossible or disproportionate effort" carve-out applies only to the third-party notification obligation, not to the business's own deletion duty or the duty to direct service providers and contractors.
CPPA regulations require a service provider or contractor to cooperate with the business in responding to a verifiable consumer request and, at the direction of the business, to delete (or enable the business to delete) personal information and notify its own service providers or contractors to delete. 11 CCR § 7022(c)(1). A service provider or contractor is not required to comply with a deletion request if it is reasonably necessary to maintain the consumer's personal information under one of the nine statutory exceptions in § 1798.105(d). 11 CCR § 7022(c)(2).
Record of deletion requests — § 1798.105(c)(2)
A business may maintain a confidential record of deletion requests solely for the purpose of (a) preventing personal information of a consumer who has submitted a deletion request from being sold, (b) compliance with laws, or (c) other purposes solely to the extent permissible under § 1798.105(d). § 1798.105(c)(2). This provision permits a business to maintain an internal record (such as a hashed identifier or email address) to honor the consumer's deletion request on an ongoing basis without re-collecting the deleted data, but the record must be confidential and limited to the stated purposes.
Source: Cal. Civ. Code § 1798.105 Source: 11 CCR § 7022 (CPPA Regulations, Requests to Delete) Source: CPPA FAQ — Consumer Rights
Right to opt out of sale or sharing — § 1798.120 and opt-out preference signals (Global Privacy Control)
California consumers have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties to stop doing so. Cal. Civ. Code § 1798.120(a)(1). This right may be referred to as the "right to opt out of sale or sharing." A business that receives an opt-out direction is prohibited from selling or sharing the consumer's personal information after receipt of the direction unless the consumer subsequently provides consent to resume the sale or sharing. § 1798.120(d).
Broad statutory definitions of "sale" and "sharing"
The CCPA/CPRA defines "sale" expansively as "selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's personal information by the business to a third party for monetary or other valuable consideration." Cal. Civ. Code § 1798.140(ad)(1) (emphasis added). The phrase "monetary or other valuable consideration" sweeps in disclosures made in exchange for anything of value—not only cash payments but also barter arrangements, discounts, access to data or services, or participation in data cooperatives. The statute enumerates eight exceptions that do not constitute a "sale," including consumer-directed disclosures, disclosures to service providers or contractors acting under a written contract with specified restrictions, and disclosures pursuant to a merger, acquisition, bankruptcy, or other asset transaction in which the third party assumes control of all or part of the business and remains subject to the CCPA. § 1798.140(ad)(2).
"Sharing" is defined separately as "sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration." Cal. Civ. Code § 1798.140(ah)(1) (emphasis added). "Cross-context behavioral advertising" means the targeting of advertising to a consumer based on the consumer's personal information obtained from the consumer's activity across businesses, distinctly-branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the consumer intentionally interacts. § 1798.140(k). Sharing thus captures disclosures to advertising platforms and data brokers for purposes of retargeting or behavioral profiling, even when no money changes hands.
The breadth of these definitions means that the opt-out right reaches most third-party disclosures of personal information for commercial purposes. The Attorney General and the CPPA have taken the position that disclosures through third-party cookies, advertising pixels, social-media plug-ins, and similar tracking technologies typically constitute "sale" or "sharing" unless the third party qualifies as a service provider or contractor under a compliant written contract.
Two opt-out mechanisms — § 1798.135
A business that sells or shares consumers' personal information must provide two methods for consumers to exercise the opt-out right:
- "Do Not Sell or Share My Personal Information" link. The business must provide a clear and conspicuous link on its internet homepage, titled exactly "Do Not Sell or Share My Personal Information," to an internet web page that enables a consumer (or a person authorized by the consumer) to opt out. Cal. Civ. Code § 1798.135(a)(1). The business may combine this link with the "Limit the Use of My Sensitive Personal Information" link into a single alternative opt-out link. § 1798.135(a)(3); 11 CCR § 7015. The opt-out page must not require the consumer to create an account or provide additional information beyond what is necessary to direct the business not to sell or share. § 1798.135(c)(1).
- Opt-out preference signal (Global Privacy Control). A business must treat an opt-out preference signal as a valid request to opt out of sale/sharing submitted pursuant to § 1798.120. Cal. Civ. Code § 1798.135(b)(1); 11 CCR § 7025. An opt-out preference signal is a signal sent by a platform, technology, or mechanism (such as a browser extension, browser setting, or device setting) that communicates the consumer's choice to opt out. The signal must be (a) in a format commonly used and recognized by businesses (e.g., an HTTP header field or JavaScript object) and (b) configured to make clear to the consumer that it is meant to opt them out of sale/sharing. 11 CCR § 7025(b). The Global Privacy Control (GPC) is the most widely deployed opt-out preference signal; it is a technical specification that transmits an
Sec-GPC: 1HTTP header and anavigator.globalPrivacyControlJavaScript property.
When a business receives an opt-out preference signal, it must treat the signal as a valid request to opt out for that browser or device, for any consumer profile associated with that browser or device (including pseudonymous profiles), and—if the consumer is known to the business—for the consumer's account and any offline sale or sharing of the consumer's personal information. 11 CCR § 7025(f)(1). The business must apply the opt-out in a frictionless manner—meaning the business honors the signal without requiring further consumer action, displays confirmation that the opt-out has been honored, and does not charge a fee or require the consumer to provide additional information (beyond what the signal conveys) to process the request. § 7025(f). The business may notify the consumer that the opt-out preference signal conflicts with the consumer's current privacy settings and may offer the consumer an opportunity to consent to the sale or sharing of their personal information, but the business must process the opt-out request unless the consumer instructs otherwise. § 7025(f)(3).
A business that elects to honor opt-out preference signals in a frictionless manner and meets the additional requirements of 11 CCR § 7025(g) is not required to post the "Do Not Sell or Share My Personal Information" link on its homepage, provided the business still includes a notice of the right to opt out in its privacy policy and describes how consumers can implement an opt-out preference signal. § 7025(g); § 1798.135(b)(1).
No verification required; 12-month opt-in wait
A business may not require a consumer to verify their identity in order to submit an opt-out request. Cal. Civ. Code § 1798.120(c); 11 CCR § 7026(g). The opt-out right is exercisable without friction. A business may deny an opt-out request only if it has a good-faith, reasonable, and documented belief that the request is fraudulent, in which case it must inform the requestor that it will not comply and provide an explanation. 11 CCR § 7026(g).
Once a consumer has opted out, the business must wait at least 12 months before requesting that the consumer authorize the sale or sharing of the consumer's personal information. Cal. Civ. Code § 1798.135(c)(5). The business may use any personal information collected from the consumer in connection with the opt-out request solely for the purpose of complying with the request. § 1798.135(c)(6).
Minors under 16 — affirmative opt-in required
Notwithstanding the general opt-out framework, a business shall not sell or share the personal information of consumers under 16 years of age unless (a) the consumer is at least 13 and less than 16 years of age and has affirmatively authorized the sale or sharing, or (b) the consumer is less than 13 years of age and the consumer's parent or guardian has affirmatively authorized the sale or sharing. Cal. Civ. Code § 1798.120(c). A business that willfully disregards a consumer's age is deemed to have had actual knowledge of the consumer's age. This is sometimes called the "right to opt in" for minors—the default is no sale or sharing, and the minor (or parent/guardian) must take affirmative action to permit it.
Source: Cal. Civ. Code § 1798.120 Source: Cal. Civ. Code § 1798.135 Source: Cal. Civ. Code § 1798.140 Source: 11 CCR §§ 7025–7026 (Opt-Out of Sale or Sharing, CPPA Regulations) Source: CPPA FAQ — Consumer Rights
Right to know — disclosure requirements under §§ 1798.110 and 1798.115
The CCPA/CPRA right to know is anchored in two core statutory provisions: (1) Cal. Civ. Code § 1798.110 (right to know what personal information has been collected), and (2) Cal. Civ. Code § 1798.115 (right to know what personal information has been sold, shared, or disclosed for a business purpose). These remain effective and substantively unchanged by the California Legislature since Proposition 24. However, effective January 1, 2026, significant CPPA regulatory amendments clarify and expand the operational obligations of businesses handling right-to-know requests under both provisions.
Right to know what information has been collected — § 1798.110
A consumer may request the following from a business:
- The categories of personal information collected (§ 1798.110(a)(1));
- Categories of sources (§ 1798.110(a)(2));
- Business/commercial purpose for collection, selling, or sharing (§ 1798.110(a)(3));
- Categories of third parties to whom personal information is disclosed (§ 1798.110(a)(4));
- The specific pieces of personal information collected (§ 1798.110(a)(5)).
Right to know what information has been sold, shared, or disclosed — § 1798.115
For sold/shared/disclosed data, a business must provide:
- Categories of personal information collected (§ 1798.115(a)(1));
- Categories of personal information sold or shared, the categories of third parties for each category (§ 1798.115(a)(2));
- Categories of personal information disclosed for a business purpose, and each category of recipient (§ 1798.115(a)(3)).
Material regulatory change: expanded pre-12-month data access (effective January 1, 2026)
Historically, the CCPA right to know applied to the 12-month period preceding the request. Under the January 1, 2026 CPPA regulations, if a business collects and retains personal information for more than 12 months, consumers may request access to all personal information collected beyond that initial 12-month period. (See 11 CCR §§ 7020(j), 7024(a)(2)(A), eff. Jan. 1, 2026.) A business must inform consumers, in its privacy policy, of the lookback period available for requests and describe the process for requesting access to information collected before the trailing 12-month period.
Other operative rules (statutory and regulatory)
- Responses must be made within 45 days (extendable once for an additional 45 days with notice).
- Twice-per-12-month frequency cap remains in effect (§ 1798.130(b)).
- Categories disclosed must map to the statutory taxonomies of § 1798.140(v)(1) and/or § 1798.80(e); regulations reiterate that custom business categories may only supplement, not replace, statutory categories (11 CCR § 7020(c)).
- Businesses are not required to disclose certain sensitive items (e.g., Social Security numbers, financial account numbers, account passwords) in response to a request for specific pieces of information (§ 1798.130(a)(2)(A)).
- The statutory definitions of "sold," "shared," and "disclosed for a business purpose" are unchanged. (See § 1798.140(ad), (ah), (f)).
Practical compliance note Businesses retaining data more than one year must evaluate historic data-mapping and access controls to ensure compliance with pre-12-month right-to-know requests beginning January 1, 2026. Failure to honor such requests is likely to result in heightened regulatory scrutiny.
Source: Cal. Civ. Code § 1798.110 Source: Cal. Civ. Code § 1798.115 Source: 11 CCR § 7020 (CPPA Regulations, effective Jan. 1, 2026) Source: 11 CCR § 7024 (CPPA Regulations, Lookback Period, effective Jan. 1, 2026)
Right to limit use of sensitive personal information — § 1798.121 trigger, permitted purposes, and 15-day compliance window
California consumers have the right, at any time, to direct a business that collects sensitive personal information about the consumer to limit its use of that sensitive personal information to uses that are necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services. Cal. Civ. Code § 1798.121(a). This right—introduced by the California Privacy Rights Act (CPRA, Proposition 24) and operative January 1, 2023—is narrower than the right to opt out of sale/sharing under § 1798.120. It does not prohibit all use or disclosure of sensitive personal information; rather, it restricts use or disclosure to a statutorily defined safe harbor of permitted purposes.
Definition of sensitive personal information
Sensitive personal information is a subset of personal information defined at Cal. Civ. Code § 1798.140(ae). The statute enumerates eleven categories:
- Social Security, driver's license, state identification card, or passport number
- Account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account
- Precise geolocation (within a radius of 1,850 feet)
- Racial or ethnic origin, religious or philosophical beliefs, or union membership
- Contents of a consumer's mail, email, and text messages (unless the business is the intended recipient)
- Genetic data
- Biometric information processed for the purpose of uniquely identifying a consumer
- Personal information collected and analyzed concerning a consumer's health
- Personal information collected and analyzed concerning a consumer's sex life or sexual orientation
- Citizenship or immigration status
- Neural data (added by AB 3286, effective January 1, 2025), defined as information generated by measuring the activity of a consumer's central or peripheral nervous system and that is not inferred from nonneural information
The definition is exhaustive—if a data element is not on the list, it is not sensitive personal information for purposes of § 1798.121.
The narrow trigger — use or disclosure beyond "reasonably expected" services
The right to limit is triggered only when a business uses or discloses sensitive personal information for purposes other than those necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services. § 1798.121(a). A business that uses or discloses sensitive personal information only for the permitted purposes set forth in the statute and CPPA regulations does not trigger the right to limit and is not required to post a "Limit the Use of My Sensitive Personal Information" link on its homepage. 11 CCR § 7027(m); Cal. Civ. Code § 1798.135(a)(2).
The statute cross-references four enumerated "business purposes" from Cal. Civ. Code § 1798.140(e) that are always permitted and do not trigger the right to limit:
- § 1798.140(e)(2) — Detecting security incidents; protecting against malicious, deceptive, fraudulent, or illegal activity; and prosecuting those responsible for that activity
- § 1798.140(e)(4) — Debugging to identify and repair errors that impair existing intended functionality
- § 1798.140(e)(5) — Short-term, transient use, including nonpersonalized advertising shown as part of a consumer's current interaction with the business, provided the consumer's personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer's experience outside the current interaction
- § 1798.140(e)(8) — Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by the business
CPPA regulations at 11 CCR § 7027(m) enumerate additional permitted purposes that mirror the remaining § 1798.140(e) business purposes and clarify the scope of the safe harbor. When a business uses or discloses sensitive personal information solely for one or more of these purposes, the business is not required to offer the right to limit. The regulation specifies that permitted purposes include:
- Performing services on behalf of the business (service-provider and contractor uses under § 1798.140(e)(1))
- Preventing, detecting, and investigating security incidents (§ 1798.140(e)(2))
- Resisting malicious, deceptive, fraudulent, or illegal actions and prosecuting those responsible
- Ensuring the physical safety of natural persons
- Short-term, transient use (§ 1798.140(e)(5))
- Performing services such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business (§ 1798.140(e)(1))
- Undertaking internal research for technological development and demonstration (§ 1798.140(e)(6))
- Improving, upgrading, or enhancing services or devices (§ 1798.140(e)(8))
The "reasonably expected by an average consumer" standard is objective. It evaluates what a reasonable consumer—not the specific individual making the request—would anticipate when interacting with the business in the context in which the sensitive personal information was collected. CPPA regulations at 11 CCR § 7002(b) provide factors for assessing reasonable consumer expectations, including the nature of the personal information, the context in which it was collected, the source, and the disclosures made by the business at or before collection.
Uses that trigger the right to limit
If a business uses or discloses sensitive personal information for purposes beyond the safe harbor—such as:
- Cross-context behavioral advertising or retargeting based on sensitive personal information
- Selling or sharing sensitive personal information to third parties for their own commercial purposes (although sale/sharing of sensitive PI may also implicate the opt-out-of-sale right under § 1798.120)
- Profiling or inference-drawing to predict consumer characteristics, preferences, or behavior (such as health-risk scoring, creditworthiness modeling, or employment screening based on sensitive personal information)
- Disclosure to data brokers or analytics partners for uses unrelated to the services the consumer requested
—then the business must provide consumers with a notice of the right to limit and a mechanism to submit a request to limit. Cal. Civ. Code § 1798.135(a)(2); 11 CCR § 7014.
Exception — sensitive PI collected without the purpose of inferring characteristics
Sensitive personal information that is collected or processed without the purpose of inferring characteristics about a consumer is not subject to the right to limit under § 1798.121. Cal. Civ. Code § 1798.121(d); 11 CCR § 7027(a). Such information is treated as ordinary personal information for purposes of all other CCPA sections, including the right to know, the right to delete, and the right to opt out of sale/sharing. The statute does not define "inferring characteristics," but CPRA's legislative history and CPPA guidance indicate the exception applies when the business collects sensitive personal information solely for operational or transactional purposes (e.g., collecting a driver's license number to verify age at checkout) without using that information to draw inferences, build profiles, or target the consumer based on the sensitive attributes.
Notice and homepage-link requirements — § 1798.135(a)(2)
A business that uses or discloses consumers' sensitive personal information for purposes other than those authorized by § 1798.121(a) must provide a clear and conspicuous link on its internet homepage, titled exactly "Limit the Use of My Sensitive Personal Information," that enables a consumer (or a person authorized by the consumer) to limit the use or disclosure of the consumer's sensitive personal information to the permitted purposes. Cal. Civ. Code § 1798.135(a)(2); 11 CCR § 7014(b).
The business may combine this link with the "Do Not Sell or Share My Personal Information" link into a single "Alternative Opt-out Link" titled "Your Privacy Choices" or "Your California Privacy Choices," provided the combined link directs consumers to a webpage that informs them of both rights and allows them to exercise both. § 1798.135(a)(3); 11 CCR § 7015.
The business must also provide a Notice of Right to Limit in its privacy policy, describing the consumer's right to limit and instructing how to submit a request. 11 CCR § 7014(f). If the business does not operate a website, it must establish and document an offline method (e.g., a toll-free telephone number or a mailed form) by which consumers can submit requests to limit. 11 CCR § 7014(e)(2).
Opt-out preference signals (Global Privacy Control)
A business must treat an opt-out preference signal as a valid request to limit the use of sensitive personal information. Cal. Civ. Code § 1798.135(b)(1); 11 CCR § 7025(a). The Global Privacy Control (GPC) is the most widely deployed opt-out preference signal; it transmits an HTTP header (Sec-GPC: 1) and a JavaScript property (navigator.globalPrivacyControl) indicating the consumer's intent to opt out of sale/sharing and to limit use of sensitive personal information.
When a business receives an opt-out preference signal, it must honor the signal in a frictionless manner—meaning the business processes the request without requiring further consumer action, displays confirmation, and does not charge a fee or demand additional information. 11 CCR § 7025(f). The business must apply the limit to the browser or device that sent the signal, to any consumer profile associated with that browser or device, and—if the consumer is known to the business—to the consumer's account and any offline use or disclosure of the consumer's sensitive personal information. § 7025(f)(1).
15-business-day compliance window
Upon receipt of a request to limit (whether submitted via the homepage link, an offline method, or an opt-out preference signal), a business must stop using or disclosing the consumer's sensitive personal information for purposes other than the permitted purposes as soon as feasibly possible, but no later than 15 business days from the date the business receives the request. 11 CCR § 7027(g)(1). This 15-day deadline is shorter than the 45-day response window for requests to know, delete, or correct. The regulation does not define "as soon as feasibly possible," but CPPA guidance indicates the business should implement the limitation immediately if technically feasible (e.g., by updating a database flag or suppressing the consumer's sensitive personal information from the data feeds sent to advertising platforms) and document the steps taken to meet the 15-day outer limit.
No verification required
A business may not require a consumer to verify their identity in order to submit a request to limit use of sensitive personal information. Cal. Civ. Code § 1798.121(b) (by cross-reference to § 1798.135(c)); 11 CCR § 7027(c). The request must be honored without friction. A business may deny a request to limit only if it has a good-faith, reasonable, and documented belief that the request is fraudulent. 11 CCR § 7027(c).
Effect of consumer direction
Once a business receives a consumer's direction to limit, the business is prohibited from using or disclosing the consumer's sensitive personal information for any purpose other than the permitted purposes unless the consumer subsequently provides consent for the use or disclosure for additional purposes. Cal. Civ. Code § 1798.121(b). The statute does not prescribe the form of subsequent consent, but it must be affirmative and voluntary; the business may not condition provision of goods or services on withdrawal of the limitation. The business must wait at least 12 months before requesting that the consumer authorize resumed use or disclosure of the sensitive personal information for non-permitted purposes. Cal. Civ. Code § 1798.135(c)(5) (cross-applying the opt-out-of-sale 12-month rule).
Service providers and contractors
A service provider or contractor that assists a business in performing the permitted purposes authorized by § 1798.121(a) may not use the sensitive personal information, after it has received instructions from the business and to the extent it has actual knowledge that the personal information is sensitive personal information, for any other purpose. Cal. Civ. Code § 1798.121(c). Service providers and contractors are not required to honor a consumer's request to limit directly—the obligation runs to the business, and the business must direct its service providers and contractors to comply. 11 CCR § 7050(j).
Recordkeeping and consumer-request metrics
A business must maintain records of consumer requests to limit and the business's responses for at least 24 months. 11 CCR § 7101(a). Businesses that process personal information of 10 million or more consumers in the preceding calendar year must compile and publish annual consumer-request metrics in their privacy policy, including the number of requests to limit received, the number complied with in whole or in part, the number denied, and the median and mean number of days within which the business substantively responded. 11 CCR § 7102(a).
Source: Cal. Civ. Code § 1798.121 Source: Cal. Civ. Code § 1798.135 Source: Cal. Civ. Code § 1798.140 Source: 11 CCR § 7027 (CPPA Regulations, Requests to Limit Use and Disclosure of Sensitive Personal Information) Source: 11 CCR § 7014 (Notice of Right to Limit) Source: 11 CCR § 7025 (Opt-Out Preference Signals)
Right to correct inaccurate personal information — statutory framework and business obligations under Cal. Civ. Code § 1798.106 and 11 CCR §§ 7023–7024
California consumers have the right to request that a business correct inaccurate personal information the business maintains about them. This right is codified in Cal. Civ. Code § 1798.106 and implemented through California Privacy Protection Agency (CPPA) regulations 11 CCR §§ 7023–7024. Notably, recent statutory amendments affect business obligations and definitions relating to the correction right, most significantly through Assembly Bill 1170 (Stats. 2025, Ch. 67), which amends the definition of "verifiable consumer request" in Cal. Civ. Code § 1798.140, effective January 1, 2026. The regulatory framework below reflects both current obligations and the effective 2026 change.
Scope and Intake Process Consumers may submit correction requests for any personal information a business maintains about them, regardless of whether it was collected directly, sourced from third parties, or inferred (11 CCR § 7023(a)). Businesses must provide at least two intake methods and follow the same intake requirements as delete/know requests (11 CCR § 7024(a)). The business must act on the request within 45 days, extendable once for another 45 days if reasonably necessary and with notice to the consumer (Cal. Civ. Code § 1798.130(a)(2); 11 CCR § 7024(b)).
Verification and Correction Standard Businesses must verify the consumer's identity to a "reasonably high degree of certainty" before processing a correction request (11 CCR § 7023(d); see also § 7060(c)(2)-(3); § 7062(c)). If the consumer’s identity cannot be verified, the business may deny the request (Cal. Civ. Code § 1798.106(c); 11 CCR § 7023(d)).
Effective January 1, 2026, the definition of "verifiable consumer request" under § 1798.140 is further clarified to include the standard for correction requests, aligning statutory and regulatory requirements for verification and triggering compliance with amended definitions (AB 1170, 2025 Cal. Legislature).
After conducting a reasonable investigation, if the business determines the data is more likely than not inaccurate, it must correct the information across its systems (11 CCR § 7023(h)(1)). If correction is not possible, deletion is permitted (11 CCR § 7023(h)(2)). The business must instruct relevant service providers and contractors to make the correction or deletion, and notify third parties unless impossible or disproportionate (11 CCR § 7023(h)(3)).
Disputed Third-Party and Inferred Data For information obtained from third parties or inferences (like consumer profiles), the business must consider documentation from the consumer (11 CCR § 7023(e)-(f)). If accuracy cannot be verified, the business must inform the consumer of the outcome and its reasoning (11 CCR § 7023(g)).
Denial Grounds and Data Minimization A business may deny correction requests if manifestly unfounded/excessive or if retention is required by law (11 CCR § 7023(k)-(l)). All data minimization principles apply (Cal. Civ. Code § 1798.100(c); 11 CCR § 7023(i)).
Recordkeeping Businesses must document requests and their responses for at least 24 months (11 CCR § 7101(a)).
Key changes: Effective January 1, 2026, the definition of verifiable consumer request under § 1798.140 is amended (per AB 1170) and directly applies to right-to-correct requests, aligning statute and regulations for verification.
Source: Cal. Civ. Code § 1798.106 Source: Cal. Civ. Code § 1798.140, as amended by AB 1170 (effective Jan. 1, 2026) Source: 11 CCR §§ 7023–7024 (CPPA Regulations, effective March 29, 2023; updated Jan. 1, 2026)
Right to data portability — delivery format, technical feasibility, and statutory exclusions under Cal. Civ. Code § 1798.130(a)(2)
California consumers who exercise the right to know the specific pieces of personal information a business holds about them (not just categories) are entitled to receive that data in a format that allows for data portability. Cal. Civ. Code § 1798.130(a)(2)(A)(iii) requires the business to produce this information “in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit this information from one entity to another entity without hindrance.”
The statute does not define “portable” or “readily usable,” but CPPA regulations clarify that if the information is maintained in a structured format (such as in a database or other machine-readable system), the business must provide it in a format that is portable and, to the extent technically feasible, readily usable by the consumer. This generally points to structured, machine-readable formats like CSV, JSON, or XML if the information is already maintained that way. Where data is unstructured or inherently in a non-portable form, the business may provide it in the format in which it is maintained, as long as it is reasonably accessible to the consumer (11 CCR § 7020(a)-(b)).
Upon a verifiable consumer request, these portability obligations apply only to disclosure of specific pieces of information under Cal. Civ. Code § 1798.110(a)(5); they do not require category-level disclosures in the same format. The response must cover the 12-month period preceding the request unless the business elects to extend the look-back period.
By law, the following cannot be released in response to a portability request, even if held in the records: Social Security numbers, driver’s license numbers, other government ID numbers, financial account numbers, health insurance numbers, medical identification numbers, account passwords or security questions/answers (Cal. Civ. Code § 1798.130(a)(2)(A)(iii)).
Delivery must be free of charge and within 45 days, extendable once by an additional 45 days when reasonably necessary (with timely notice), consistent with the general CCPA/CPRA response timeline. (See Cal. Civ. Code § 1798.130(a)(2)(B).)
Source: Cal. Civ. Code § 1798.130 Source: Cal. Civ. Code § 1798.110 Source: 11 CCR § 7020 (CPPA Regulations, effective Jan. 1, 2026)
Right to non-discrimination and financial incentives — Cal. Civ. Code § 1798.125 and financial incentive regulations
California Civil Code § 1798.125 prohibits businesses from discriminating against a consumer for exercising any right provided by the CCPA/CPRA. Discrimination, under § 1798.125(a)(1), includes: denying goods or services, charging different prices or rates (including through discounts or penalties), providing a different level or quality of goods or services, or suggesting such differences based solely on the consumer’s exercise of a privacy right (such as accessing, deleting, or opting out of sale/sharing of their personal information).
However, the statute permits exceptions for price or service differences and financial incentives (such as loyalty programs, rewards, or payments for data) if the differential is "reasonably related to the value provided to the business by the consumer's data" (§ 1798.125(a)(2)-(b)). This safe harbor is most relevant for rewards and loyalty programs, where businesses offer benefits in exchange for data. To rely on this exception, a business must:
- Provide a clear and accessible Notice of Financial Incentive before enrollment (§ 1798.125(b)(2); 11 CCR § 999.307). Statutory requirements mandate that the notice include a summary of the program, material terms, the categories of personal information implicated, a good-faith estimate of the value of consumer data (and the method used), and instructions for opting in and withdrawing.
- Obtain prior, informed opt-in consent from the consumer; participation must be freely given and revocable. Withdrawal must be honored promptly, and the business may not request opt-in consent again for at least 12 months after withdrawal (§ 1798.125(b)(3)).
- Avoid any incentive or program that is deemed unjust, unreasonable, coercive, or usurious. The term "unjust, unreasonable, coercive, or usurious" is not fully defined in statute or regulation. As of June 2026, neither the CPPA nor AG has published regulatory examples or guidance specifying precise practices deemed per se unlawful in this category. Unable to confirm as of 2026-06-16.
Material 2026 regulatory change — No default selection or prominent placement of incentives
Effective January 1, 2026, CPPA regulations expressly prohibit businesses from pre-selecting consumers by default into financial incentive programs or presenting enrollment options more prominently than mechanisms to exercise opt-out rights (see 11 CCR § 999.307 and § 999.337; CPPA Final Regulation Text and Statement of Reasons). This means companies must not use default settings, auto-enrollment checkboxes, or visually emphasize rewards signup over opt-out or privacy controls.
Valuation and documentation of consumer data
Valuation of consumer data must be documented by method: 11 CCR § 999.337 (in the consolidated CPPA regulations PDF) specifies acceptable approaches, including marginal or average value, aggregate revenue or profit, or a reasonably reliable alternative. The business must be able to explain how the value of the consumer's data supports the offered differential.
Enforcement is vested in both the California Attorney General (statutory) and the California Privacy Protection Agency (for administrative enforcement and rulemaking, as of July 2023). Ongoing and future rulemakings may refine or add obligations, especially concerning notice content, program eligibility, or calculation methods. Practitioners should monitor both statutory text and regulatory updates.
Source: Cal. Civ. Code § 1798.125 Source: 11 CCR § 999.307, § 999.337 (CPPA Regulations, consolidated PDF, eff. Jan. 1, 2026) Source: CPPA Final Statement of Reasons, Sept. 2025
Right to appeal denial of consumer data requests — updated 11 CCR § 7021 procedure, covered request types, and 45-day response window (effective Jan. 1, 2026)
Effective January 1, 2026, California businesses are required to provide consumers with the right to appeal a denial of a covered data subject request pursuant to 11 CCR § 7021. This marks a material change from prior guidance, which had referenced 11 CCR § 7012 for the appeal process. The operative rule is now § 7021, as adopted in the CPPA's final regulations published in 2024 and entering into force in 2026.
Scope: Which consumer requests can be appealed?
11 CCR § 7021 covers appeals by consumers when a business denies any covered data subject request related to automated decisionmaking technology (ADMT), access, deletion, or correction. The regulation explicitly includes requests to appeal ADMT-related decisions, as well as the traditional requests to know (access), delete, or correct personal information. The rule does not require an appeal process for requests to opt out of sale/sharing or to limit use/disclosure of sensitive personal information.
Notification and accessibility
When a business denies a covered consumer request, it must promptly notify the consumer of the reason for denial and provide clear and accessible instructions describing how to submit an appeal (§ 7021(b)). The appeal process must be at least as accessible as the means for submitting the original request (webform, toll-free number, etc.). The regulation prohibits high-friction or burdensome measures for appeals except where strictly necessary for security, fraud prevention, or harm mitigation, and only to the extent needed for those purposes (§ 7021(c)).
Appeal review and response timeframe
Following receipt of an appeal, a business must review and respond within 45 calendar days (§ 7021(e)). This period may be extended once by up to an additional 45 days if reasonably necessary, provided the consumer is notified of the extension and given a reason within the original 45-day period. The response must specify the outcome of the appeal (upheld or reversed), the reasoning, and, if denied, provide the CPPA’s contact information and notice of the consumer’s right to file a complaint (§ 7021(f)).
Recordkeeping and publication of metrics
All businesses must maintain records of received consumer appeals and outcomes for at least 24 months (§ 7101(a)). Businesses processing the personal information of 10 million or more consumers annually must publish summary metrics on requests and appeal responses as required by § 7102(a).
Effective date and compliance note
The requirements and citation change to 11 CCR § 7021 take effect January 1, 2026. Sections referencing 11 CCR § 7012 for these appeal obligation are now superseded. Businesses should ensure their compliance documentation, consumer-facing instructions, and regulatory citations are updated accordingly for requests received on or after the 2026 effective date.
Source: 11 CCR § 7021 (CPPA Regulations, Appeals, effective Jan. 1, 2026) Source: 11 CCR § 7101, § 7102 (CPPA Regulations, Recordkeeping and Metrics)
Limits on frequency and grounds for denial of consumer data requests — twice-per-12-month cap and manifestly unfounded/excessive requests
California law places statutory boundaries on how often a consumer may exercise certain data access rights and defines lawful bases for a business to deny requests. The twice-per-12-month cap and the ability to refuse manifestly unfounded or excessive requests are central limitations under the CCPA/CPRA.
Twice-per-12-month frequency cap for access requests
A business is not obligated to provide personal information disclosures pursuant to a right-to-know request more than twice within any 12-month period for the same consumer. This applies to requests made under Cal. Civ. Code § 1798.110 (what the business has collected) or § 1798.115 (what was sold, shared, or disclosed), as specified by § 1798.130(b). There is no statutory cap for deletion, correction, opt-out, or limit requests, based on current authority. Source: Cal. Civ. Code § 1798.130
Manifestly unfounded or excessive requests and administrative fees (effective Jan. 1, 2026)
The CCPA/CPRA, as updated by California Privacy Protection Agency regulations effective January 1, 2026, authorizes a business to refuse or charge a reasonable fee for requests that are "manifestly unfounded or excessive." The regulation (11 CCR § 7023(l)) provides that if a request is clearly repetitive, harassing, or lacks any reasonable basis, a business may: (1) refuse to act on the request, or (2) charge a fee reflecting the administrative cost. The business must demonstrate and communicate to the consumer why the request was deemed unfounded or excessive and what fee, if any, will be charged. This codifies a safeguard for businesses against abusive or bad-faith consumer requests under the new regulatory regime. These provisions apply to requests handled after January 1, 2026.
Other denial grounds—for example, inability to verify a requestor, statutory carve-outs (such as for Social Security numbers or legal obligations), or appeals requirements—are addressed separately in the statute, specific regulations, or covered in other sections of this guide.
Source: Cal. Civ. Code § 1798.130 Source: 11 CCR § 7023 (effective Jan. 1, 2026)
Household data requests — statutory definition, verification hurdles, and denial rules for household information under Cal. Civ. Code § 1798.140(j) and 11 CCR § 7021
The CCPA/CPRA explicitly covers personal information collected about a “household” in addition to individuals. “Household” is defined at Cal. Civ. Code § 1798.140(j) as “a group, however identified, of consumers who cohabitate with one another at the same residential address and share use of common devices or services.” This definition is broader than traditional family or single-account constructs and creates operational ambiguity for businesses, especially in smart-home, shared-device, ISP, and utility contexts.
Right-to-know, deletion, and correction requests for household data
Where a business holds personal information at the household level, requests to know, delete, or correct such data trigger special handling requirements under both the statute and CPPA regulations (see 11 CCR § 7021):
- If all consumers in the household jointly make the request, a business must handle it as if it were an individual request, subject to standard verification. The business may require joint action and verification from each member.
- If an individual requestor submits a request regarding household data, but not all household members join, the business must respond only if (1) the requestor is verified, (2) the business can separately verify every household member, and (3) the requestor is authorized to receive the household information. If these conditions are not met, the business may deny the request. (11 CCR § 7021(c).)
- Where consumers are under age 13, the parent or guardian may exercise household requests on their behalf, subject to age-specific verification procedures.
Verification and risk threshold
Businesses must use a verification level that accounts for the sensitivity of both the household data and the risk of harm if the information were improperly disclosed (11 CCR § 7021(b)). The business may consider account authentication processes, proof of residence, and other factors. When household verification is not possible due to insufficient information or technical limits, the business must deny the request and notify the requestor.
Denial and partial disclosure obligations
If a request cannot be verified at the required level, or if not all household members consent (and are verified), a business must deny the request. However, it may still disclose any data solely pertaining to the requesting, verified consumer. (11 CCR § 7021(e).)
No household rights for deidentified or aggregate data
The business is not obligated to respond to household data requests where the information is maintained only in deidentified or aggregate form, and cannot be re-linked to any consumer, consistent with statutory and regulatory limitations (Cal. Civ. Code §§ 1798.140(m), 1798.145(a)(5)).
Practical notes (2026 currency)
Proper household handling is especially relevant for utilities, connected-home platforms, ISPs, group video streaming, and landlord-tenant relationships. Failure to follow joint-consent or verification procedures is a repeat AG and CPPA enforcement theme, especially where businesses have supplied household-level data to one member without proper checks. Guidance as of June 2026 directs businesses to define and document their household-verification protocols and be prepared to demonstrate compliance for each household request processed.
Source: Cal. Civ. Code § 1798.140(j) Source: 11 CCR § 7021 (CCPA Regulations, Household Data Requests)
Right to request a list of third parties who received personal information — Cal. Civ. Code § 1798.115(c) and business-purpose disclosures
California Civil Code § 1798.115(c) gives consumers the right, upon a verifiable request, to obtain from a business "a list of the categories of third parties to whom the business disclosed a consumer’s personal information for a business purpose in the preceding 12 months, by category or categories of personal information for each category of third parties." This right is distinct from the right to know what personal information was collected (Cal. Civ. Code § 1798.110) and focuses on onward transfers for operational needs.
What businesses must disclose
- The business must provide, for the preceding 12 months, a summary table showing: (1) the categories of personal information collected about the consumer; (2) the categories of personal information sold and the corresponding categories of third parties to whom it was sold; and (3) the categories of personal information disclosed for a business purpose, along with each category of third-party recipient. The third-party recipient categories might include advertising networks, cloud providers, payment processors, affiliates, or customer support vendors—but the law requires disclosure by category only, not by individual company name.
- Businesses are not required by the statute to identify specific companies—only the recipient category. However, if the business’s category mapping is so narrow that a category describes a unique entity, the disclosure will effectively name that third party. As of June 2026, neither statute nor regulation requires the business to list the name of each company receiving the consumer’s information for a business purpose. Unable to confirm as of 2026-06-16 whether additional CPPA interpretive guidance has altered this practice.
Meaning of "business purpose"
- Disclosures "for a business purpose" are defined at Cal. Civ. Code § 1798.140(e), not § 1798.115. Common business purposes include fulfilling orders, providing customer service, processing payments, or conducting analytics—typically involving service providers or contractors under a written contract with statutory use restrictions.
- This right does not cover data "sold" or "shared" for cross-context behavioral advertising, as covered in Cal. Civ. Code § 1798.120 (opt-out of sale/sharing).
Operational note vs. statutory rule
- The requirement to track categories of recipients for business-purpose disclosures places a recordkeeping and data-mapping burden on businesses. This is not spelled out in the text of § 1798.115 but is a practical compliance implication.
Source: Cal. Civ. Code § 1798.115
Right to access inferences drawn about the consumer — statutory treatment and disclosure requirements under CCPA/CPRA
California law treats “inferences drawn” from other personal information as a discrete category of personal information subject to data subject rights, including access, correction, and deletion. An inference is defined in Cal. Civ. Code § 1798.140(v)(1)(K) as "inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes."
Scope and statutory enumeration Businesses must identify and disclose inferences under both the right to know (Cal. Civ. Code § 1798.110) and the right to request an accounting of what was sold/shared/disclosed (Cal. Civ. Code § 1798.115). Inferences are a separate statutory category—the law treats them distinctly from the raw data used to construct them. The CPPA regulations clarify that businesses must disclose both the underlying personal information (such as purchase history) and the inferences drawn from it (such as an assigned interest in travel or a creditworthiness score) upon a verifiable consumer request. (See 11 CCR § 7020(c), effective Jan. 1, 2026.)
How inferences must be disclosed A business must provide the actual inferences it maintains for the consumer, not just the categories. The disclosure should include the profile, segment, or prediction linked to the consumer, whether the inference was generated internally or obtained from a third party. The CPPA has clarified that providing a generic description (e.g., "We may infer your interests...") is insufficient. Instead, the business must produce the specific inferences it holds about the requesting individual, such as “Affinity: Adventure Traveler” or “Predicted Income Range: $90,000–$120,000.” (11 CCR § 7020(c)(1)(H); CPPA Guidance, 2023.)
Operational requirements and correction rights When processing an access or correction request, the business must locate and disclose not just original source data (like transactions or browsing history) but all inferences derived from any category of personal information about the consumer. If a consumer disputes an inference, the business is obligated to investigate and, if the inference is more likely than not inaccurate, must correct or delete it and notify service providers/contractors as required (Cal. Civ. Code § 1798.106; 11 CCR § 7023(h)).
Practical compliance note The CPPA and Attorney General have identified inference disclosure as a high-priority enforcement area, focusing on businesses that profile consumers for targeted advertising, risk scoring, or eligibility determinations. CPPA rulemaking and enforcement advisories (2023-2026) emphasize that vague or incomplete inferences disclosures violate the CCPA/CPRA. Businesses should audit their data flows and ensure that all inferences, profiles, or predictive scores generated using personal information are mapped and disclosed as required. As of June 2026, no final CPPA enforcement action has further narrowed or expanded the definition or compliance expectation for inferences. Unable to confirm as of 2026-06-16 whether additional binding guidance has been issued since January 2026.
Source: Cal. Civ. Code § 1798.140 Source: 11 CCR § 7020 (CPPA Regulations, Disclosure of Inferences)