The California Consumer Privacy Act, as amended by the CPRA, gives consumers rights over the personal information businesses collect, and requires notice at collection, opt-outs of sale and sharing, and limits on sensitive personal information.
For-profit businesses that meet a revenue threshold, buy/sell/share large volumes of personal information, or derive significant revenue from selling it.
California residents, with additional protections when the personal information relates to minors.
Process on the business's behalf under contract terms that restrict further use.
"Sale" and "sharing" (for cross-context behavioural advertising) both trigger opt-out obligations.
The categories and specific pieces of personal information collected, and the sources, purposes and recipients.
Request deletion of personal information, subject to statutory exceptions.
Request correction of inaccurate personal information (added by the CPRA).
Via a "Do Not Sell or Share My Personal Information" link and recognised opt-out signals.
Limit use and disclosure of sensitive personal information to specified purposes.
Not to be discriminated against for exercising these rights.
Disclose categories collected and the purposes, at or before the point of collection.
Provide the "Do Not Sell or Share" link and honour Global Privacy Control signals.
Verify and respond to consumer requests within statutory timelines.
Collect and retain only what is reasonably necessary and proportionate.
Impose CPRA terms on service providers, contractors and third parties.
Maintain reasonable security procedures appropriate to the information.
The CPRA created a category of sensitive personal information, government IDs, financial account details, precise geolocation, race or religion, health, and the contents of communications, and gave consumers the right to limit its use.
SSNs, driver's licence, financial account and payment details.
Location data that identifies a specific place.
Health, sex life, racial or ethnic origin, religious beliefs.
| Mechanism | Detail |
|---|---|
| Regulator | California Privacy Protection Agency and the Attorney General investigate and enforce. |
| Administrative fines | Per-violation penalties, higher for violations involving minors. |
| Private right of action | Consumers may sue for statutory damages after certain data breaches. |
General information, not legal advice, applicability depends on your specific processing and revenue.
We build your notices, opt-out mechanisms, GPC handling, request workflows and vendor contracts, and prepare the evidence that shows they work.