CCPA / CPRA

Consumer Rights Under the CCPA: What California Residents Can Require

Key Takeaways

  • The statute creates rights to know, delete, correct, opt out of sale or sharing, limit sensitive data use, portability and non-discrimination
  • Businesses have 45 days to respond, extendable once by a further 45 days with notice
  • The right to delete carries nine enumerated exceptions, so a valid request does not always compel deletion
  • Opt-out preference signals transmitted by a browser must be honored as a valid request
  • The private right of action is confined to certain data breaches, not to violations of these rights generally

The Rights the Statute Creates

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives residents a defined set of rights against businesses that meet its applicability thresholds. They operate independently of one another, and a business can satisfy one while failing another.

RightWhat it entitles a resident toPrincipal limits
Know / accessCategories and specific pieces of personal information collected, sources, purposes, and categories of recipientsCertain sensitive identifiers are never disclosed in response; requests may be limited in frequency
DeleteDeletion of personal information collected from the consumerNine statutory exceptions
CorrectCorrection of inaccurate personal informationBusiness may consider the totality of circumstances and documentation
Opt out of sale or sharingDirection to stop selling or sharing personal informationDoes not reach disclosures to service providers under compliant contracts
Limit sensitive personal informationRestriction of use to enumerated permitted purposesApplies only where use exceeds those purposes
PortabilityThe data in a readily usable, portable format where technically feasibleApplies to information provided electronically
Non-discriminationNo penalty for exercising a rightFinancial incentives permitted if reasonably related to value

Access, Deletion and Correction Mechanics

The right to know has two layers. A consumer may ask for the categories of personal information collected, the sources, the business or commercial purposes, and the categories of third parties to whom it was disclosed. A consumer may separately ask for the specific pieces of personal information held about them, which is the more operationally demanding request because it requires assembling records across systems.

The CPRA amendments extended the lookback period. Where a consumer requests information beyond the preceding twelve months, a business is required to provide it for the period on and after January 1, 2022, unless doing so proves impossible or would involve disproportionate effort. That qualifier is narrow rather than general.

The right to delete applies to personal information the business collected from the consumer. It carries nine enumerated exceptions, which is why a valid, verified request does not always result in deletion. The exceptions cover completing a transaction the consumer requested, detecting security incidents and prosecuting those responsible, debugging, exercising free speech, complying with the California Electronic Communications Privacy Act, engaging in public-interest research meeting specified conditions, internal uses reasonably aligned with consumer expectations, complying with a legal obligation, and other internal lawful uses compatible with the context of collection.

A business that denies deletion on one of these grounds is required to say so and to identify the basis. Where deletion is granted, the obligation extends to notifying service providers, contractors and, in specified circumstances, third parties to whom the information was sold or shared.

The right to correct arrived with the CPRA. A business receiving a verified request is required to use commercially reasonable efforts to correct inaccurate information, and may consider the totality of circumstances relating to the contested data, including documentation the consumer provides.

Opt-Out of Sale and Sharing

The statute treats sale and sharing as distinct. Sale means disclosing personal information to a third party for monetary or other valuable consideration. Sharing was added by the CPRA and captures disclosure for cross-context behavioral advertising, whether or not money changes hands. That second definition is what brings most advertising technology arrangements within the opt-out even where no payment flows for the data itself.

A business that sells or shares personal information is required to provide a clear and conspicuous link titled “Do Not Sell or Share My Personal Information,” or to use an alternative opt-out mechanism the regulations permit. Disclosures to a service provider or contractor under a contract containing the terms the statute specifies are neither a sale nor sharing, which is the practical reason those contract terms matter.

Limiting Sensitive Personal Information

Sensitive personal information is a defined category covering government identifiers, financial account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail, email and text messages where the business is not the intended recipient, genetic data, biometric information processed to identify a consumer, health information, and information about sex life or sexual orientation.

The right here is narrower than an opt-out. A consumer may direct a business to limit use and disclosure to what is necessary to perform the requested services or provide the goods, together with a set of enumerated permitted purposes such as security, fraud prevention and short-term transient use. The right is triggered only where a business uses or discloses sensitive personal information beyond those purposes; a business staying within them has nothing to offer a consumer to limit.

Opt-Out Preference Signals

The regulations require businesses to process an opt-out preference signal transmitted by a platform, technology or mechanism, where that signal meets the specified requirements. Global Privacy Control is the implementation that has seen the widest adoption.

The consequence is structural rather than cosmetic. A signal arrives before any interaction with a consent interface, so honoring it depends on the backend rather than on a banner. Enforcement attention has repeatedly landed on businesses whose interface presented an opt-out that the underlying systems did not carry out, and on businesses that recognized a signal for some data flows but not others.

Scope questions follow from the mechanism. A signal is transmitted by a browser or device rather than by an identified person, so it applies to the consumer in that context. Where a business can associate the signal with a known account, the regulations contemplate applying the opt-out to that consumer more broadly, and asking the consumer whether they intend it to apply beyond the device. What a business may not do is treat the signal as ambiguous and therefore ignorable, or present a conflicting interface choice as overriding it.

Response Deadlines and Verification

A business is required to confirm receipt of a request within ten business days and to describe how it will be processed. Substantive response is due within 45 calendar days of receipt, a period that includes the time taken to verify the requester. The deadline may be extended once by a further 45 days where reasonably necessary, provided the consumer is notified within the first 45-day window and given the reason.

Verification is required before disclosing or deleting personal information, and the standard scales with the sensitivity of what is requested. The regulations distinguish verification to a reasonable degree of certainty from verification to a reasonably high degree of certainty, the latter applying to requests for specific pieces of personal information. A business that cannot verify a requester is required to say so rather than to respond partially without explanation.

Requests to opt out of sale or sharing are treated differently: they are not subject to verification, because requiring proof of identity to stop data flowing would itself be an obstacle. An authorized agent may submit requests on a consumer's behalf, subject to the conditions the regulations set.

Non-Discrimination and Loyalty Programs

A business may not deny goods or services, charge different prices or rates, provide a different level or quality of goods or services, or suggest that it will do any of those things, because a consumer exercised a right. The prohibition is what keeps the rights meaningful in practice rather than nominally available at a price.

The statute does not outlaw loyalty programs or differential pricing outright. It permits a business to offer financial incentives, including payments for the collection, sale or retention of personal information, and to charge different prices or offer different quality where the difference is reasonably related to the value provided to the business by the consumer's data. A business offering such a program is required to notify consumers of the material terms, obtain opt-in consent that can be revoked at any time, and refrain from programs that are unjust, unreasonable, coercive or usurious.

The reasonably-related standard requires a good-faith estimate of the value of the data and a description of the method used to calculate it. That documentation requirement is where loyalty programs most often fall short, since the price difference is typically set by marketing considerations rather than derived from data value.

Notice at Collection and the Privacy Policy

Rights are exercisable only where a consumer knows what has been collected, so the statute pairs them with disclosure duties that run whether or not anyone submits a request.

The notice at collection must be provided at or before the point of collection, and must identify the categories of personal information to be collected, the purposes for which each category will be used, whether each category is sold or shared, and the length of time the business intends to retain each category or, where that is not possible, the criteria used to determine the period. The retention element arrived with the CPRA and is the disclosure most often missing, because it requires an organization to have decided its retention periods rather than merely to describe its collection.

The privacy policy is a broader document, updated at least every twelve months, describing the rights available and the methods for submitting requests, the categories collected, sold, shared and disclosed in the preceding twelve months, the sources, the business or commercial purposes, and the categories of third parties involved. Where a business sells or shares personal information, or uses sensitive personal information beyond permitted purposes, the policy carries additional disclosures.

A business that collects personal information must provide at least two methods for submitting requests to know, though a business operating exclusively online and having a direct relationship with the consumer need only provide an email address. Methods must reflect how the business ordinarily interacts with consumers, which is why a mail-only channel offered by an online service has drawn scrutiny.

Authorized Agents

A consumer may use an authorized agent to submit requests on their behalf, and the regulations set what a business may require in response. For requests to know, delete or correct, a business may require the agent to provide signed permission from the consumer, may require the consumer to verify their own identity directly, and may require the consumer to confirm directly that they granted permission.

For opt-out requests the position is narrower, consistent with the absence of a verification requirement for opt-outs generally. A business may deny an agent's opt-out request only where the agent cannot provide signed permission demonstrating authorization.

The agent mechanism is what makes bulk opt-out and deletion services workable, and businesses receiving volumes of agent-submitted requests have limited grounds to treat them differently from requests submitted directly.

Enforcement and the Limited Private Right of Action

Two bodies enforce the statute. The California Privacy Protection Agency holds administrative enforcement authority alongside its rulemaking and audit powers. The California Attorney General retains civil enforcement authority. Administrative penalties are set per violation, with a higher figure for intentional violations and for violations involving the personal information of consumers the business knows to be under 16.

The CPRA removed the mandatory 30-day cure period that had applied under the original statute. Whether an opportunity to cure is given is now discretionary rather than guaranteed, which changed the calculus for businesses that had treated the cure window as a safety net.

The private right of action is narrow. It is available where nonencrypted and nonredacted personal information of specified categories is subject to unauthorized access and exfiltration, theft or disclosure as a result of a failure to implement and maintain reasonable security procedures. It is a data-breach cause of action, not a general right to sue over the rights described above. Statutory damages are available within a defined range per consumer per incident, or actual damages if greater.

Consumers who believe a business has not honored a request may complain to the CPPA or the Attorney General. Whether a particular set of facts supports a claim, and which route makes sense, depends on details a general guide cannot resolve.

Background

For the underlying law rather than this development: California privacy law, Technology & SaaS privacy law, Retail & E-Commerce privacy law.

Frequently Asked Questions

How long does a business have to respond to a CCPA request?
Receipt must be confirmed within ten business days, and a substantive response is due within 45 calendar days of receipt, including verification time. That deadline can be extended once by a further 45 days where reasonably necessary, provided the consumer is notified within the original window and given a reason.
Can a business refuse to delete personal information?
Yes, on any of nine enumerated grounds, including completing a requested transaction, detecting security incidents, complying with a legal obligation, and internal uses reasonably aligned with the consumer's expectations. A business relying on an exception is required to say so and identify the basis.
What is the difference between selling and sharing personal information?
Sale means disclosure to a third party for monetary or other valuable consideration. Sharing, added by the CPRA, means disclosure for cross-context behavioral advertising whether or not consideration flows. Both are subject to the same opt-out.
Does a loyalty program violate the CCPA's non-discrimination rule?
Not automatically. The statute permits financial incentives and differential pricing where the difference is reasonably related to the value the consumer's data provides to the business, subject to notice of material terms, opt-in consent that can be revoked, and a good-faith valuation with the calculation method described.
Must an opt-out request be verified?
No. Requests to opt out of sale or sharing are not subject to verification. Requests to know, delete or correct are, and the required degree of certainty is higher for requests seeking specific pieces of personal information.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.