California Data Privacy Act: Rights, Requests, and Lawsuits

The California Consumer Privacy Act, expanded by the California Privacy Rights Act in 2020, gives every California resident the right to find out what personal information a business holds about them, correct it, delete it, and stop its sale or sharing. The law applies to for-profit companies that do business in California and meet at least one size or data-use threshold, and it is enforced by both the California Privacy Protection Agency and the state Attorney General. Serious data breaches also open the door to private lawsuits.

What You Can Demand From a Business

California residents hold five core rights, and a business covered by the law cannot charge you for exercising most of them.

A business also cannot make it harder to exercise a right than it was to hand over the data in the first place. If signing up took two clicks, deleting shouldn’t take ten. And a business cannot retaliate for opting out. It cannot deny you service, raise your price, downgrade quality, or hint that any of that will happen because you exercised a right.5California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights

There is one narrow exception. A business can offer a loyalty program, discount, or other financial incentive tied to your data, but only if the price difference is reasonably related to the value of the data, the terms are clearly described, and you opt in. You can revoke that consent anytime, and if you decline, the business must wait at least 12 months before asking again.

Sensitive Personal Information Gets Extra Protection

The law treats some categories of data as sensitive and lets you shut off most uses of them beyond what’s needed to deliver the service you requested or to detect security threats. Sensitive personal information includes:6California Privacy Protection Agency. What is Personal Information

  • Social Security, passport, driver’s license, and state ID numbers
  • Account logins paired with the access codes or passwords that unlock them
  • Precise geolocation
  • Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership
  • Contents of your mail, email, and text messages not directed to the business
  • Biometric data, genetic data, and neural data
  • Health information and information about your sex life or sexual orientation

A retailer tracking your general shopping habits is handling ordinary personal information. A fitness app logging health conditions or a navigation app recording your minute-by-minute movements is processing sensitive data, and you can tell it to stop using that data beyond the strict minimum.

Stronger Rules for Minors

For anyone under 16, the default flips from opt-out to opt-in. A business must get affirmative consent before selling or sharing a minor’s data. Teenagers between 13 and 15 give that consent themselves; for children under 13, a parent or guardian must consent. Violations involving minors’ data trigger the higher $7,500 per-incident penalty instead of the $2,500 standard fine.7California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement

Which Businesses Have to Follow the Law

The law reaches for-profit businesses that collect personal information from California residents and meet at least one of three tests:

  • Annual gross revenues over $26.625 million in the previous calendar year. The figure was originally $25 million and adjusts for inflation; the current threshold took effect January 1, 2025.8California Privacy Protection Agency. Frequently Asked Questions
  • Buying, selling, or sharing personal information of 100,000 or more consumers or households a year.
  • Deriving 50 percent or more of annual revenue from selling or sharing personal information.9California Legislative Information. California Code CIV 1798.140 – Definitions

The business doesn’t need to be based in California. If it does business in the state and clears any threshold, it’s covered. Affiliates that share common branding with a qualifying business and receive its consumers’ data are pulled in as well when one controls the other through majority ownership or similar influence.9California Legislative Information. California Code CIV 1798.140 – Definitions

Employees, job applicants, and business-to-business contacts count too. The original CCPA temporarily exempted their data, but those exemptions expired on January 1, 2023. If you’re a California employee, you now have the same rights against your employer that you have against a retailer, including the right to know, delete, and opt out of sales.

How to Submit a Request

Start on the business’s website. Every covered business must maintain a privacy policy that explains your rights and offers at least two ways to submit a request, including a toll-free phone number. Online-only businesses with a direct consumer relationship can substitute an email address for the phone line.10California Legislative Information. California Code CIV 1798.135 – Methods of Limiting Sale, Sharing, and Use of Personal Information and Use of Sensitive Personal Information The homepage must also carry a prominent “Do Not Sell or Share My Personal Information” link, and, where the business handles sensitive data, a “Limit the Use of My Sensitive Personal Information” link.

You’ll need to provide enough identifying information to prove you are who you say you are. For most requests, that means matching your name and the email or physical address on file, or logging into your account. Requests to see specific pieces of personal information trigger stricter verification: expect to match multiple data points, and the business may ask for a signed declaration under penalty of perjury. Deletion requests use a similar but sometimes lighter check depending on how sensitive the data is.

Using an Authorized Agent

You can appoint someone else to make requests for you. The business can ask the agent for signed permission from you and can ask you to verify your identity or confirm the authorization directly. A valid California Probate Code power of attorney must be accepted without further proof, but the business cannot require a power of attorney as the only acceptable form of authorization.11Legal Information Institute. California Code of Regulations Title 11 Section 7063 – Authorized Agents

How Long the Business Has to Respond

A business has 45 calendar days to respond, counted from the day your request arrives regardless of how long verification takes. If the request is unusually complex, it can extend that by another 45 days, up to 90 days total, but it must tell you within the first 45 days that it is doing so and why.12Legal Information Institute. California Code of Regulations Title 11 Section 7021 – Timelines for Responding to Requests to Delete, Requests to Correct, and Requests to Know

What the Law Doesn’t Cover

Some information sits outside the law’s reach, mostly to avoid stepping on federal rules. Protected health information under HIPAA is exempt, along with the healthcare entities that handle it that way. Personal financial data governed by the Gramm-Leach-Bliley Act and credit-related information under the Fair Credit Reporting Act are also carved out. Clinical trial data collected under federal human-subjects protections is exempt, and publicly available government records or information you yourself made public without restricting the audience fall outside the definition of personal information altogether.13California Legislative Information. California Code CIV 1798.145 – Exemptions

These are data-level exemptions, not blanket exemptions for whole companies. A bank’s GLBA-regulated customer records are exempt, but the same bank’s rewards-app data may not be. And even where a company’s data is otherwise exempt under GLBA or FCRA, the private lawsuit right for data breaches still applies.

Enforcement and Penalties

The California Privacy Protection Agency, a five-member board created by the CPRA, runs day-to-day enforcement through audits, investigations, and administrative proceedings.7California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement The state Attorney General keeps independent authority to bring its own cases, and has, including a $2.75 million settlement with Disney over allegations the company failed to honor consumer requests.14State of California – Department of Justice – Office of the Attorney General. Privacy Enforcement Actions

Administrative fines run up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a minor’s data.7California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement Those numbers are per violation, so one compliance failure affecting thousands of consumers can produce very large liability. The CPPA has been active, bringing 2025 enforcement actions against a national clothing retailer, Honda, a Fortune 500 company, and multiple data brokers that failed to register.15California Privacy Protection Agency. Latest News and Announcements

One shift matters here. The original CCPA gave businesses a mandatory 30-day window to fix violations before facing penalties. The CPRA eliminated that guarantee. The CPPA has discretion to offer a cure period but isn’t required to; enforcement can move directly to fines with no warning.

Suing After a Data Breach

You can sue a business directly in one situation: your nonencrypted, nonredacted personal information is exposed in a breach because the business failed to maintain reasonable security. Statutory damages run from $100 to $750 per consumer per incident, or actual damages, whichever is greater.16California Legislative Information. California Code, Civil Code CIV 1798.150 – Personal Information Security Breaches

Before filing for statutory damages, you must give the business 30 days’ written notice identifying the provisions violated. If the business actually cures the violation within that window and provides a written statement that it has done so and that no further violations will occur, you cannot pursue statutory damages. Tightening security after a breach is not, by itself, a cure of the breach. And if the business later breaks its written promise, you can sue on the original breach plus any new violations.17State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

No pre-suit notice is needed if you’re suing only for actual financial losses instead of statutory damages. Class actions under this section are common, and with even the $100 floor multiplied across a large user base, the exposure for companies with weak security can be substantial.