California Right to Know Act: Requests, Disclosures, and Penalties

California’s right to know lets you require a covered business to tell you exactly what personal information it holds about you, where it got that information, why it collected or sold it, who else received it, and the specific data points on file. The right sits inside the California Consumer Privacy Act, as expanded by the California Privacy Rights Act, and it applies to for-profit businesses that meet the state’s revenue or data-volume thresholds. Requests are free, and the business generally has 45 days to answer.

What You Can Ask a Business to Disclose

Under Civil Code 1798.110, a verified request obligates the business to give you five things: the categories of personal information it has collected about you, the categories of sources that information came from, the business or commercial purpose for collecting or selling it, the categories of third parties that received it, and the specific pieces of personal information the business is holding on you.1California Legislative Information. California Civil Code 1798.110 The obligation runs the same whether the business sold your data outright or handed it to service providers and affiliates.

You should also see much of this information before you ever ask. At or before the point of collection, businesses must tell you what categories they plan to collect, what they plan to do with it, and how long they intend to keep it.2California Legislative Information. California Civil Code 1798.100 That up-front disclosure typically lives in a privacy notice. The right to know backs it up: if a company’s public notice is vague or incomplete, you can force a specific accounting of your own data.

The right to know is bounded in time. It covers the 12-month period preceding your request, so you cannot pull records going back indefinitely.

What Counts as Personal Information

The CCPA defines personal information broadly. It includes anything that identifies, relates to, or could reasonably be linked to a specific consumer or household. Names, email addresses, Social Security numbers, and phone numbers are the obvious examples, but the definition also reaches IP addresses, browsing history, purchase records, geolocation data, and profiles businesses build about you from your online behavior.3California Privacy Protection Agency. What Is Personal Information

Data collected in the background through cookies, web beacons, and other tracking technologies counts too. A business that records your browser type, the referring site, or your IP address without you typing anything into a form is still collecting personal information under the law.3California Privacy Protection Agency. What Is Personal Information Even data that looks anonymous on its own qualifies when combining it with other information could identify you.

Sensitive Personal Information

A subset of data gets extra protection as “sensitive personal information”:

  • Social Security numbers, passport numbers, and driver’s license or state ID numbers
  • Bank account, debit card, or credit card numbers combined with any access code or password
  • Precise geolocation data
  • Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership
  • Contents of your emails, texts, and other messages, unless you sent them directly to the business
  • Biometric and genetic information, including neural data
  • Information about your health, sex life, or sexual orientation

You can direct a business to limit use of sensitive personal information to only what is necessary to provide the goods or services you asked for.4California Legislative Information. California Code, Civil Code CIV 1798.121 A business that wants to use it beyond those purposes has to tell you and give you the option to restrict that use.5State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

How to Submit a Request

Covered businesses must offer at least two methods for submitting a request, including a toll-free phone number. Businesses that run a website must also provide an online request form. There is no fee.

Before releasing anything, the business must verify your identity. For a request to know, that usually means matching information you supply against records the business already has. When you ask for the specific pieces of personal information on file, expect a stricter verification step, because that is the version of the request that produces the most detailed disclosure. The business must deliver those specific pieces in a structured, commonly used, machine-readable format so you can review the data and, if you want, move it elsewhere.

Timing is set by statute. The business has 45 days to respond. It can extend once by another 45 days when reasonably necessary, but it has to notify you of the extension inside the original window.6California Legislative Information. California Code, Civil Code CIV 1798.130

A business cannot punish you for asking. Charging you more, providing a lower quality of service, or refusing service because you exercised the right to know violates the law. Financial incentives for allowing data collection are allowed only with your opt-in consent and only when the incentive is reasonably related to the value your data provides.

When a Business Can Refuse

A business that denies your request must explain why. If the refusal looks improper, or if the business ignores you altogether, you can file a complaint with the California Attorney General’s office or the California Privacy Protection Agency. Both share enforcement authority: the Attorney General investigates and brings civil actions, and the CPPA handles rulemaking, audits, and compliance directives.7California Legislative Information. California Civil Code 1798.185

Which Businesses Have to Answer

The right to know only reaches for-profit entities doing business in California that hit at least one of three thresholds:8California Legislative Information. California Civil Code 1798.140

  • Annual gross revenue over $26,625,000 as of the preceding calendar year (the figure is adjusted periodically from the original $25 million baseline)9California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
  • Annually buying, selling, or sharing the personal information of 100,000 or more consumers or households
  • Deriving 50 percent or more of annual revenue from selling or sharing consumers’ personal information

Entities that a qualifying business controls and shares branding with are also covered, which prevents a company from routing data through a subsidiary to duck compliance. Nonprofits and government agencies fall outside the definition of “business” and are not subject to the right to know.8California Legislative Information. California Civil Code 1798.140

One point worth flagging for workers and small-business owners: the temporary carve-outs for employee data and business-to-business contact information expired on January 1, 2023, and the legislature did not renew them. Personal information collected in the employment context and in B2B transactions is now fully covered. If you are a California employee or a contact at a business customer, you can use the right to know against a covered company just as any consumer can.

Some data types are exempt even when the business is covered. Medical information handled under HIPAA and California’s Confidentiality of Medical Information Act is carved out, as is clinical trial data under federal human-subject protections. Personal information already regulated under the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act is also excluded from the main CCPA rules.10California Legislative Information. California Civil Code 1798.145 A hospital or bank is not exempt from the CCPA as an institution; the exemption follows the regulated data, not the entity, so records outside those federal regimes remain in reach.

Penalties for Businesses That Don’t Comply

Civil penalties are assessed per violation. As of 2025:

  • Up to $2,663 per unintentional violation
  • Up to $7,988 per intentional violation
  • Up to $7,988 per violation involving the personal information of a consumer the business knew was under 16

Those figures replaced the original $2,500 and $7,500 amounts and are adjusted periodically.11California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases Because each violation counts separately, a single noncompliant practice affecting a large customer base can produce fines well into the millions.

Individual consumers cannot sue over a right-to-know violation on their own. The private right of action under the CCPA is limited to data breaches involving unencrypted personal information caused by a business’s failure to maintain reasonable security, with statutory damages of $100 to $750 per consumer per incident or actual damages, whichever is greater.12California Legislative Information. California Code, Civil Code CIV 1798.150 For everything else under the CCPA, including refusals to answer a right-to-know request, enforcement runs through the Attorney General and the CPPA.