California Consumer Privacy Act: Rights, Requests, and Enforcement

The California Consumer Privacy Act is a state law that gives California residents enforceable rights over the personal information that businesses collect about them. You can find out what a company knows about you, ask it to delete or correct that information, tell it to stop selling or sharing your data, and restrict how it uses the most sensitive categories. Businesses that ignore these rights face civil penalties of up to $2,663 per violation, rising to $7,988 for intentional violations or violations involving a minor’s data.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA The law was strengthened in 2023 by amendments from the California Privacy Rights Act, and it protects any natural person who resides in California, including residents who are temporarily out of state.

The Rights You Can Exercise

The CCPA grants a fixed set of rights that apply whether you have a paid account with a company or simply landed on its site once and had data collected about you.

Right To Know

You can ask a business to tell you what personal information it has collected about you, where it got that information, why it collected it, and which third parties received it. The response has to disclose the specific pieces of data the business holds, not just vague category labels.2California Legislative Information. California Civil Code 1798.110 – Consumers Right to Know What Personal Information Is Being Collected The disclosure is free, and it has to arrive in a format you can actually use, such as a file you could hand off to another service.3California Legislative Information. California Civil Code 1798.100

Right To Delete

You can require a business to delete the personal information it has collected from you. Once your request is verified, the business must also tell its service providers, contractors, and any third parties it sold or shared your data with to delete it too.4California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information The law recognizes exceptions. A business can hold on to data needed to complete a transaction you asked for, detect security incidents, comply with a legal obligation, or exercise free speech rights, among other reasons.

Right To Correct

If a business has inaccurate information about you, you can require it to fix the record. The business must use commercially reasonable efforts to make the correction once your identity is verified.5California Legislative Information. California Civil Code 1798.130 This right matters most when the data feeds into a decision about credit, employment, or insurance.

Right To Opt Out of Sale or Sharing

You can tell any covered business to stop selling or sharing your personal information with third parties. Once it receives the request, it must comply and cannot resume unless you later give affirmative consent.6State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) California also recognizes the Global Privacy Control, a browser-level signal that automatically communicates your opt-out preference to every website you visit. Covered businesses have to honor it as a valid opt-out.7State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC)

Right To Limit Use of Sensitive Personal Information

You can direct a business to use your sensitive personal information only for what is necessary to provide the goods or services you actually asked for. Once you send that direction, the business cannot use that data for profiling, targeted advertising, or other secondary purposes.8California Legislative Information. California Civil Code 1798.121 – Consumers Right to Limit Use and Disclosure of Sensitive Personal Information

What Counts as Personal Information

The CCPA defines personal information broadly. It covers any data that identifies, relates to, or could reasonably be linked to a particular consumer or household. That reaches well beyond your name and address to online identifiers like IP addresses, purchasing history, biometric data such as fingerprints and facial recognition patterns, geolocation, and professional or employment information.9California Legislative Information. California Civil Code 1798.140 – Definitions Information you have voluntarily made public, or information found in widely distributed media, is not covered.10California Privacy Protection Agency. Frequently Asked Questions (FAQs)

A narrower subset gets stronger protection. Sensitive personal information includes Social Security numbers, financial account credentials, precise geolocation, the contents of your mail and text messages, genetic and biometric data, health information, information about sex life or sexual orientation, and data about racial or ethnic origin, religious beliefs, or union membership.6State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) This is the category you can restrict under the right to limit.

Which Businesses Have To Honor Your Requests

The CCPA applies to for-profit companies that do business in California and meet at least one of three thresholds:9California Legislative Information. California Civil Code 1798.140 – Definitions

  • Annual gross revenue over $26,625,000 as of the most recent inflation adjustment.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
  • Buying, selling, or sharing the personal information of 100,000 or more consumers or households a year.
  • Deriving 50 percent or more of annual revenue from selling or sharing consumers’ personal information.

A parent company or subsidiary that shares branding with a covered business can also be pulled in if the entities share consumers’ personal information. Nonprofits and government agencies generally fall outside the law, and most small businesses that neither trade in personal data nor cross the thresholds are exempt.6State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

How To Send a Request

Start with the company’s online privacy policy, which every covered business has to publish. If the business sells or shares personal information, its site must include a clearly labeled “Do Not Sell or Share My Personal Information” link, or an equivalent opt-out link. You can also enable the Global Privacy Control in your browser to send an automatic opt-out signal to every site you visit.

For requests to know, delete, or correct, the business must offer at least two ways to submit, which often include a toll-free number and a web form. Before doing anything, the business has to verify who you are, so gather the identifiers it already has on file: your account email, the name on your profile, a loyalty program number, or your mailing address. If you cannot be verified to a reasonable degree of certainty, the business may deny the request to protect the actual account holder.

Using an Authorized Agent

You can designate someone else to submit privacy requests for you. The business can ask the agent to show signed written permission from you, and separately ask you to verify your identity or confirm you authorized the agent. If you have given the agent a power of attorney under California Probate Code sections 4121 through 4130, the business has to accept the request without additional verification.11Legal Information Institute. Cal. Code Regs. Tit. 11, 7063 – Authorized Agents A power of attorney cannot be required as a precondition for using an agent at all.

How Long the Business Has To Respond

The business has to acknowledge your request within 10 business days. It then has 45 calendar days from the day it received the request to deliver a substantive response, whether that means providing your data, completing a deletion, or correcting the record.5California Legislative Information. California Civil Code 1798.130 If the request is unusually complex, it can take another 45 calendar days, but you must be notified of the extension and given a reason before the first 45 days run out. A business does not have to fulfill more than two access requests from the same person in a 12-month period.3California Legislative Information. California Civil Code 1798.100

Stronger Rules for Children’s Data

For minors, the CCPA flips the default. Adults have to opt out of data sales, but a business with actual knowledge that a consumer is under 16 cannot sell or share that minor’s personal information without affirmative opt-in consent. For a child between 13 and 15, the minor gives that consent. For a child under 13, a parent or guardian has to authorize it. A business that willfully ignores a consumer’s age is treated as having actual knowledge, so pleading that it never asked will not save it. Violations involving minors’ data draw the higher penalty tier.

No Retaliation for Exercising Your Rights

A business cannot punish you for using these rights. It cannot deny you goods or services, charge you a higher price, or give you a worse version of the product because you submitted a privacy request or opted out of data sales.12California Legislative Information. California Civil Code 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights A business can still offer a financial incentive, such as a loyalty discount, in exchange for collecting or keeping your data, but only with clear notice of the material terms and a good-faith estimate of what your data is worth to the company.13Legal Information Institute. Cal. Code Regs. Tit. 11, 7016 – Notice of Financial Incentive

Enforcement and When You Can Sue

The California Privacy Protection Agency is the primary enforcer, with the power to investigate, audit businesses, and bring administrative actions.10California Privacy Protection Agency. Frequently Asked Questions (FAQs) The California Attorney General can also bring civil actions. The original law’s 30-day cure period for government enforcement was eliminated by the CPRA starting in 2023.

Civil penalties for a violation run up to $2,663, and up to $7,988 for intentional violations or those involving a minor’s personal information.1California Privacy Protection Agency. Updated Monetary Thresholds in CCPA The base statutory amounts are $2,500 and $7,500, adjusted for inflation.14California Legislative Information. California Civil Code 1798.199.90 Because they are assessed per violation, a single flawed data practice affecting thousands of consumers can produce very large liability.

You can sue directly in one situation: if your unencrypted personal information is exposed in a data breach because a business failed to maintain reasonable security practices. Statutory damages run from $100 to $750 per consumer per incident, or you can seek your actual damages if they are larger.15California Legislative Information. California Civil Code 1798.150 – Personal Information Security Breaches Before filing for statutory damages, you must give the business 30 days’ written notice identifying the specific violation. If the business actually cures the problem within that window and provides a written statement that no further violations will occur, statutory damages are off the table for that incident. This notice requirement does not apply if you are only seeking your actual financial losses.

Where the Law Does Not Reach

The CCPA does not override every other privacy law, and some categories of data carry full or partial exemptions:

  • Health data already protected under HIPAA and the California Confidentiality of Medical Information Act is exempt.
  • Personal information collected, processed, sold, or disclosed under the Gramm-Leach-Bliley Act is carved out. The exemption applies to the specific data GLBA covers, not to the entire financial institution, so a bank’s marketing data that falls outside GLBA can still be reached under the CCPA.
  • Consumer credit reporting information regulated by the Fair Credit Reporting Act is exempt, so credit bureaus can deny CCPA requests for that data.6State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

Employee and job-applicant personal information was temporarily exempt under the original CCPA, but that exemption expired on January 1, 2023. If you work for a covered California employer, the same CCPA rights now apply to the personal information your employer holds about you.