PII in California: Definition, Rights, and Enforcement

In California, personal information — often called PII — is defined far more broadly than the Social Security numbers and names people usually picture. Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, it means any data that identifies, relates to, or could reasonably be linked to you or your household.1California Legislative Information. California Civil Code 1798.140 – Definitions That reach covers IP addresses, browsing history, biometric scans, purchase records, and inferences a company draws about you, and it comes with enforceable rights to see the data, delete it, correct it, and restrict how it’s used.

What Counts as Personal Information

The “reasonably linkable” test is what makes the definition so wide. A business doesn’t need your name for data to qualify. If the information could be tied back to you by combining it with other data points, the law treats it as personal information.1California Legislative Information. California Civil Code 1798.140 – Definitions

The statute lists twelve categories:

  • Identifiers such as real name, alias, postal address, email address, Social Security number, driver’s license number, passport number, IP address, and account name.
  • Financial and customer records covered by California’s customer records statute, including bank account, credit card, and insurance policy numbers.
  • Characteristics of protected classifications under California or federal law.
  • Commercial information, meaning records of products or services purchased or considered and other purchasing or browsing tendencies.
  • Biometric information, including fingerprints, faceprints, voiceprints, and keystroke patterns.
  • Internet activity, including browsing history, search history, and how you interact with websites, apps, or advertisements.
  • Geolocation data.
  • Sensory data, meaning audio, electronic, visual, thermal, or similar information.
  • Professional or employment information, including job history and performance evaluations.
  • Education information not already publicly available under FERPA.
  • Inferences drawn from any of the above to build a profile of your preferences, characteristics, behavior, or aptitudes.
  • Sensitive personal information, a subcategory with its own protections.

The list isn’t a ceiling. Any data meeting the reasonably linkable standard qualifies, whether or not it fits one of these buckets.1California Legislative Information. California Civil Code 1798.140 – Definitions

Sensitive Personal Information

A narrower slice of personal information gets extra protection. Sensitive personal information under the CPRA includes:

  • Social Security, driver’s license, state ID, or passport numbers
  • Account login credentials combined with a password or security code that allows access to a financial account
  • Precise geolocation
  • Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership
  • The contents of your mail, email, and text messages, unless the business is the intended recipient
  • Genetic data
  • Neural data generated by measuring the activity of your nervous system
  • Biometric data processed to identify you
  • Health information
  • Information about your sex life or sexual orientation

You can direct a business to use this data only for what’s necessary to deliver the service you asked for, which is one of the strongest controls in the law.2California Legislative Information. California Code Civil Code 1798.140 – Definitions

What Isn’t Covered

Some data about you sits outside the CCPA/CPRA, and it helps to know where the line is so a business can’t overstate an exemption.

Publicly Available Information

Data lawfully obtained from federal, state, or local government records is not personal information under the law. Neither is information you’ve made available to the general public through widely distributed media, or information you’ve shared without restricting the audience. Biometric information collected without your knowledge, though, is never “publicly available,” even if it could be pulled from somewhere else.1California Legislative Information. California Civil Code 1798.140 – Definitions

De-identified and Aggregate Data

Information de-identified so it can no longer reasonably be linked back to any consumer or household is excluded, along with aggregate consumer information. Businesses relying on this exclusion have to meet technical and organizational requirements to prevent re-identification.1California Legislative Information. California Civil Code 1798.140 – Definitions

Data Governed by Certain Federal Laws

Protected health information already governed by HIPAA is exempt. So is personal information subject to the Gramm-Leach-Bliley Act for financial institutions and data regulated by the Fair Credit Reporting Act. These exemptions apply to specific types of data, not to entire companies. A hospital still owes CCPA obligations for data it collects outside HIPAA’s scope, and a bank still faces CCPA requirements for information it gathers in non-financial contexts.3California Legislative Information. California Civil Code 1798.145 – Exemptions

Your Rights Over Your Personal Information

If you’re a California resident, even temporarily outside the state, you have six core rights under the CCPA/CPRA. A business cannot retaliate by charging higher prices, providing lesser service, or refusing to deal with you because you used them.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act Employees and business contacts are covered too; the older exemptions for those categories expired on January 1, 2023.

Know and Access

You can ask a business what categories and specific pieces of personal information it has collected about you, where it came from, why it was collected, and which third parties received it. The response has to come in a format you can readily use and move to another company.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

Delete

You can request that a business delete personal information it collected from you and pass that instruction to its service providers. Exceptions exist. A business may keep data it needs to complete a transaction, detect security incidents, comply with a legal obligation, or use internally in ways a reasonable consumer would expect based on the relationship.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

Opt Out of Sale or Sharing

You can tell a business to stop selling your personal information or sharing it for cross-context behavioral advertising. Sharing here means disclosing data to a third party for targeted advertising, whether money changes hands or not.5California Legislative Information. California Civil Code 1798.140 – Definitions Businesses must also honor opt-out preference signals like the Global Privacy Control browser setting. When a business detects that signal, it has to treat the visit as an opt-out for that browser, device, and any linked consumer profile.6New York Codes, Rules and Regulations. California Code of Regulations 7025 – Opt-Out Preference Signals

Correct

If a business holds inaccurate personal information about you, you can ask it to fix the record.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

Limit Use of Sensitive Personal Information

You can direct a business to use your sensitive personal information only for what’s necessary to provide the service you requested. Without that restriction, data like precise location or a genetic profile can be put to uses well beyond the reason you handed it over.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

Freedom From Dark Patterns

Consent a business obtains through a “dark pattern” — a user interface designed to undermine real choice — doesn’t count under the law. In practice, the opt-out path can’t be longer, harder to find, or more confusing than the path to agree.7California Privacy Protection Agency. Enforcement Advisory No. 2024-02

How to Make a Request

Covered businesses have to offer at least two ways for you to submit requests to know, delete, or correct. That means a toll-free phone number at a minimum, plus an online submission method if the business runs a website. Online-only businesses with a direct consumer relationship can substitute an email address for the phone number.8California Legislative Information. California Civil Code 1798.130

The business must respond within 45 days of receiving your request. It can extend that once by another 45 days if it notifies you inside the first window. The response is free.8California Legislative Information. California Civil Code 1798.130

Requests have to be verifiable, so the business will need to confirm you are who you say you are before releasing or erasing data. Reasonable authentication is allowed, but a business cannot make you create an account just to submit a request. If you already have one, it can require you to use it.8California Legislative Information. California Civil Code 1798.130

If a Business Breaks the Rules

The California Privacy Protection Agency is the primary enforcer, and the Attorney General also has authority. Penalties are assessed per violation, so the numbers scale quickly across a large customer base. Unintentional violations carry fines of up to $2,500 each; intentional violations, and any violation involving the data of a consumer the business knows is under 16, run up to $7,500. Both amounts get periodic inflation adjustments.9California Legislative Information. California Civil Code 1798.155 – Administrative Enforcement

You have a limited right to sue on your own when a data breach exposes your unencrypted personal information because a business failed to maintain reasonable security practices. Statutory damages run from $100 to $750 per consumer per incident, or actual damages if greater.10California Legislative Information. California Code Civil Code 1798.150 The statute doesn’t name a specific security framework, but California courts have pointed to industry benchmarks such as the Center for Internet Security’s controls as reference points. A business that skips basic security and then suffers a breach can face the CPPA and affected consumers at the same time.