CPRA Employee Data: Rights, Requests, and Breach Remedies

If you work in California for a mid-size or large employer, the California Privacy Rights Act gives you rights over the personal information your employer collects about you. Those employee data rights under the CPRA took effect on January 1, 2023, when a temporary carve-out for worker and business-to-business information expired.1Bloomberg Law. Employment, Overview – CCPA/CPRA Scope for Employers, Employee Data You can ask to see what’s in your file, correct errors, delete data the employer doesn’t need to keep, stop the sale or sharing of your information, and limit how sensitive data gets used. Your employer cannot retaliate against you for doing any of it.

Is Your Employer Covered

The law only reaches for-profit businesses that do business in California, collect personal information from California residents, and meet at least one of three thresholds:2California Legislative Information. California Code CIV 1798.140 – Definitions

  • Annual gross revenue above $25 million in the prior calendar year
  • Buying, selling, or sharing the personal information of 100,000 or more consumers or households each year
  • Deriving 50 percent or more of annual revenue from selling or sharing personal information

Most mid-size and large California employers clear the $25 million line without difficulty. If yours doesn’t hit any of the three thresholds, the CPRA’s employee provisions don’t apply to it. The reason employees are covered at all is that the statute defines “consumer” to mean any California resident, which sweeps workers, applicants, and independent contractors into the same framework as retail customers.2California Legislative Information. California Code CIV 1798.140 – Definitions

What Data the Law Covers

Personal information is defined broadly: anything that identifies, relates to, or could reasonably be linked to a specific person or household.2California Legislative Information. California Code CIV 1798.140 – Definitions For workers, that reaches well past the HR file. The statute expressly names professional and employment-related information, internet and network activity data, geolocation data, and inferences drawn from any of it to build a profile of you. Browsing history on a company laptop, badge-swipe logs, and productivity monitoring output are all in scope.

A subset called “sensitive personal information” gets stronger treatment. It includes:2California Legislative Information. California Code CIV 1798.140 – Definitions

  • Government identifiers such as Social Security, driver’s license, and passport numbers
  • Financial account or card numbers combined with access credentials
  • Precise geolocation (GPS-level, not city or zip)
  • Racial or ethnic origin, religious beliefs, or union membership
  • Biometric data used to identify you, including fingerprints, facial recognition templates, and voiceprints
  • Genetic and neural data
  • Health information collected and analyzed by the employer
  • The contents of personal mail, email, or text messages, unless the employer is the intended recipient

Fingerprint time clocks, GPS on fleet vehicles, and wellness screenings all pull in sensitive information, and the right to limit sensitive-data use only exists for this category.

The Rights You Actually Have

California workers get five core rights, matching the ones consumers have when dealing with retailers or tech platforms.3State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)

  • Right to know. You can request the specific pieces of personal information the employer has collected, the sources, the business purposes, and the categories of third parties who received it. You get up to two free requests per year.
  • Right to correct. If your file has inaccurate information, you can direct the employer to fix it.
  • Right to delete. You can ask the employer to erase personal data, subject to real limits described below.
  • Right to opt out of sale or sharing. If your employer transfers employee data to analytics vendors, advertising networks, or data brokers, you can shut that off.
  • Right to limit sensitive personal information. You can restrict use of sensitive data to what’s reasonably necessary to perform your job or provide the services you’d expect, keeping it out of secondary uses like profiling.

You Cannot Be Retaliated Against

The CPRA explicitly bars employers from retaliating against any employee, applicant, or independent contractor who uses these rights.4California Legislative Information. California Code CIV 1798.125 – Consumers Right of No Retaliation Following Opt Out or Exercise of Other Rights That means no denial of services, no change to compensation, no degradation of work conditions, and no suggestion that filing a request will lead to consequences. The statute names workers specifically rather than borrowing a general consumer clause.

Why Deletion Has Limits

An employer cannot delete your tax withholding records or stop processing your Social Security number for payroll. The law allows retention of data required for legal compliance, contract performance, and other necessary business functions. Deletion and limitation work best against data the employer collects but doesn’t strictly need: surplus monitoring logs, location tracking beyond what operations require, or recruiting materials with no ongoing purpose.

How to Make a Request

Covered employers generally offer at least two intake channels, usually a designated email address and a secure online portal. Before you submit, decide what you want: a full copy of everything the company holds on you, a correction to specific records, or deletion of particular categories. A precise ask cuts down on back-and-forth that eats into the response clock.

Your employer must verify your identity before releasing anything. The regulations require a documented, reasonable verification process, usually built on information the company already has on file.3State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Current employees typically clear this easily. Former employees may need to supply additional identifying details.

You can also designate an authorized agent, either a person or a business entity registered with the Secretary of State, to submit the request for you. The employer can require signed proof of your authorization and may still ask you to verify your identity directly.3State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) This mostly matters when a lawyer or privacy service handles the process on your behalf.

Response Deadlines

Once your employer receives a request to know, delete, or correct, it has 45 calendar days to respond. The clock starts the day the request arrives, regardless of how long verification takes.5Legal Information Institute. Cal. Code Regs. Tit. 11, 7021 – Timelines for Responding to Requests to Delete, Requests to Correct, and Requests to Know The employer may extend by another 45 days for complex requests, capped at 90 days total, but only if it notifies you of the extension and the reason within the first 45. If it can’t verify your identity within the initial window, it can deny the request.

What You Can Recover After a Data Breach

The CPRA gives workers a limited private right of action, and only for breaches. If your employer fails to maintain reasonable security practices and your unencrypted personal information is stolen or exposed as a result, you can sue for statutory damages of $100 to $750 per person per incident, or actual damages, whichever is greater.6California Legislative Information. California Code CIV 1798.150 – Civil Action You don’t have to prove identity theft or financial loss to collect the statutory amount.

There’s a procedural step. Before filing for statutory damages, you must give the employer 30 days’ written notice identifying the provisions violated. If the employer actually cures the problem within those 30 days and provides a written statement that the violation is fixed and won’t recur, you lose the right to sue for statutory damages on that breach.6California Legislative Information. California Code CIV 1798.150 – Civil Action Tightening security after the fact does not count as a cure for a breach that already happened. If the employer breaks that written promise, damages become available for every subsequent breach.

Separately, the California Privacy Protection Agency enforces the law on its own, with administrative fines up to $2,500 per violation, or $7,500 for each intentional violation and for violations involving anyone the business knows is under 16.7California Legislative Information. California Code CIV 1798.155 – Administrative Enforcement Those are per-violation figures, which scale quickly when an employer mishandles data across a large workforce.

Where Federal Law Steps In Instead

The CPRA does not override every federal privacy regime. Health information handled by a covered entity or business associate under HIPAA’s privacy, security, and breach notification rules is carved out, so an employer running a self-administered health plan doesn’t face duplicate obligations for that specific data. The exemption only covers information actually maintained under HIPAA standards. Health-adjacent data collected outside that framework, such as wellness program survey answers sitting in a general HR database, still falls under the CPRA.

Background check information governed by the Fair Credit Reporting Act gets a similar exemption. A credit report or criminal background check pulled through a consumer reporting agency is regulated by the FCRA, not the CPRA. The exemption does not reach employment decisions the employer makes using that information or other data collected during the same hiring process.

These carve-outs attach to the data, not to the employer. A healthcare company still has to comply with the CPRA for any employee personal information that falls outside HIPAA, including website cookies, marketing data, and ordinary HR records that aren’t protected health information.