California’s data privacy law gives residents the right to see, delete, correct, and stop the sale of the personal information that businesses collect about them. The framework is built from the California Consumer Privacy Act and the amendments added by the California Privacy Rights Act, and it reaches nearly every for-profit company of meaningful size that handles data on Californians. Businesses that ignore it face administrative fines of up to $7,988 per intentional violation, and consumers can sue directly when weak security lets their information leak in a data breach.
Your Rights as a California Resident
Six rights sit at the center of the law, and you can exercise any of them against a covered business at no cost.
- Know what a business has on you. You can request the specific pieces of personal information a business has collected, the categories of sources it came from, the business purpose behind the collection, and the categories of third parties that received your data through sale or sharing.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
- Delete it. You can ask the business to erase personal information it collected from you, and it must instruct its service providers and contractors to do the same. Some legally required retention creates exceptions.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
- Correct it. If the record is wrong, you can demand a fix.
- Opt out of sale or sharing. You can tell a business to stop selling your data or sharing it for cross-context behavioral advertising. Once you opt out, it cannot resume without your later authorization.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
- Limit the use of sensitive data. You can restrict a business to using your sensitive personal information only for what is necessary to deliver the service you asked for.2California Privacy Protection Agency. What Is Personal Information
- Not be punished for exercising these rights. A business cannot deny you service, raise your price, or downgrade your experience because you filed a privacy request.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
What Counts as Personal Information
Personal information is defined broadly: anything that identifies, relates to, or could reasonably be linked to you or your household.2California Privacy Protection Agency. What Is Personal Information Names, email and home addresses, purchase history, browsing activity, location data, employment records, and IP addresses all qualify. So do profiles a business builds about you, even under a pseudonym.
A subset gets stronger protection as “sensitive personal information.” That tier covers Social Security numbers, passport and driver’s license numbers, precise geolocation, racial or ethnic origin, religious beliefs, genetic data, financial account details, and the contents of private communications like emails and texts.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) The right to limit sensitive-data use applies only to this category.
Which Businesses Have to Comply
The law reaches for-profit companies that do business in California and meet at least one of three thresholds:
- Annual gross revenue above $26,625,000 in the prior calendar year, an amount adjusted upward from the original $25 million through required inflation indexing.3California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
- Annually buying, selling, or sharing personal information of 100,000 or more consumers or households.
- Deriving 50 percent or more of annual revenue from selling or sharing consumer data.4California Legislative Information. California Civil Code 1798.140
The business does not have to be headquartered in California. If it collects data from California residents and hits any threshold, it is covered. Nonprofits and government agencies are generally exempt.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
One change worth knowing if you are dealing with a current or former employer: the carve-outs that used to exclude employee data and business-to-business contact information expired on January 1, 2023. Employees, job applicants, and business contacts of covered companies now have the same privacy rights as any other consumer.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
What the Law Does Not Cover
Some data is regulated by federal law instead. These carve-outs are type-of-data exemptions, not blanket business exemptions: a hospital or bank must still comply with California privacy law for any data it holds that falls outside the federal scheme.5California Legislative Information. California Civil Code 1798.145
- Protected health information governed by HIPAA, and HIPAA-covered providers to the extent they handle patient data the same way.
- Personal information subject to the Gramm-Leach-Bliley Act, but only data collected in connection with financial products or services.
- Information handled by consumer reporting agencies and data furnishers under the Fair Credit Reporting Act, only to the extent it is used according to that law.
- Data collected in federally regulated clinical trials or biomedical research, provided it is not sold outside those purposes.
How to Make a Request
Start with the business’s privacy policy, usually linked at the bottom of its website. The policy must explain what data is collected, why, and how to submit a request.6California Legislative Information. California Civil Code 1798.100 A business that sells or shares personal information must also post a clearly labeled “Do Not Sell or Share My Personal Information” link.
Most companies accept requests through an online form, a dedicated email address, or a toll-free number. You will need to verify your identity, usually by confirming account details or a recent transaction. Sensitive-data or deletion requests may require additional proof. You can also designate an authorized agent to file on your behalf; the agent must be registered with the California Secretary of State and hold your signed written permission, and the business can still verify your identity directly.
Response Timelines
The business must acknowledge your request within 10 business days, describing the verification process and the expected timeline. A substantive response is due within 45 calendar days of receipt. One extension of up to 45 additional days is allowed with written notice and a reason, for a hard maximum of 90 days. If the business cannot verify your identity within the initial 45-day window, it may deny the request.7Cornell Law Institute. Cal. Code Regs. Tit. 11, 7021 – Timelines for Responding to Requests
Global Privacy Control: The One-Click Option
Filing separate opt-out requests with every company that has your data is not realistic. Global Privacy Control is a browser-based signal that sends an automatic opt-out to every site you visit. California law requires covered businesses to treat a GPC signal as a legally valid consumer request to stop selling or sharing personal information.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) GPC is built into several browsers and available as an extension, and enabling it takes about 30 seconds.
Extra Protection for Minors
A business that knows a consumer is under 16 cannot sell or share that consumer’s personal information without affirmative opt-in consent. For teenagers ages 13 through 15, the teenager must authorize it. For children under 13, a parent or guardian must give consent.8California Legislative Information. California Civil Code 1798.120 A business that willfully disregards a consumer’s age is treated as having actual knowledge, so companies with reason to expect underage users cannot simply avoid asking. Violations involving the data of consumers under 16 carry the higher fine tier of up to $7,988 per incident.9California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for Fines and Monetary Thresholds
Fines and Lawsuits
The California Privacy Protection Agency handles administrative enforcement, and the state Attorney General can also sue.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)9California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for Fines and Monetary Thresholds10California Legislative Information. California Civil Code 1798.155 Because fines are assessed per violation, a single case involving thousands of consumers can add up quickly.
The original 30-day window a business had to fix a violation before facing penalties expired on January 1, 2023. The CPPA can now pursue fines immediately.
When You Can Sue Directly
Individual consumers can sue a business in one narrow situation: when unencrypted and unredacted personal information is stolen, exposed, or disclosed because the business failed to maintain reasonable security. The same right applies when the leak involves your email address paired with a password or security question that would let someone into your account.11California Legislative Information. California Civil Code 1798.150
Statutory damages run from $107 to $799 per consumer per incident, or actual damages, whichever is greater, adjusted upward from the original $100 to $750 range.3California Privacy Protection Agency. Updated Monetary Thresholds in CCPA Before suing for statutory damages, you have to send the business written notice of the specific violation and give it 30 days to cure the problem. If the business genuinely fixes the issue and commits in writing to stop, statutory damages are off the table for that breach. Tightening security after the fact does not count as “curing” a breach that has already occurred.11California Legislative Information. California Civil Code 1798.150
What Is Changing Soon
Two developments will expand what you can do with the law.
The Delete Act (SB 362) targets data brokers who buy, aggregate, and resell consumer data. Any business meeting the data-broker definition must register annually with the CPPA by January 31 and disclose whether it collects data on minors, tracks precise geolocation, or handles reproductive health care data. The centerpiece is a single-request deletion mechanism the CPPA must launch by January 1, 2026. Once it is live, you will be able to submit one verified request that reaches every registered data broker. Beginning August 1, 2026, brokers must check the system at least every 31 days and process all pending deletions.12LegiScan. Bill Text CA SB362 – 2023-2024 Regular Session
New rules on automated decision-making technology, finalized by the CPPA in 2025, take effect on January 1, 2026, though businesses that use these systems to make significant decisions do not have to comply with the specific ADMT requirements until January 1, 2027.13California Privacy Protection Agency. California Finalizes Regulations to Strengthen Consumers’ Privacy The regulations cover systems that replace or substantially replace human judgment, including profiling, and will require notice to consumers and rights to opt out and appeal decisions made by such systems.