California Consumer Rights: A Complete CCPA and CPRA Guide
A practical guide to California consumer rights under the CCPA and CPRA. Learn the seven rights, response deadlines, opt-out signals, and penalties.
If your website has visitors from California, you are dealing with California consumer rights whether or not you have thought about them. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives residents of the state seven enforceable rights over the personal information businesses collect about them. This guide explains each right, who has to honor it, the deadlines involved, and what happens when businesses get it wrong. It is educational content rather than legal advice, so talk to a qualified privacy attorney about your specific situation.
What Are California Consumer Rights?
California consumer rights are the privacy entitlements granted to California residents by the CCPA, codified at California Civil Code Sections 1798.100 through 1798.199.100. They let residents find out what personal information a business holds about them, get it deleted or corrected, stop its sale or sharing, and limit how sensitive data is used, without being penalized for asking.
Two things make these rights distinct from privacy protections elsewhere. First, they attach to the resident, not to a customer relationship: a person who has never bought anything from you can still submit a request if you hold their data. Second, they are enforced by two separate bodies, the California Attorney General and the California Privacy Protection Agency (CPPA), the first dedicated privacy regulator in the United States.
The CPRA, approved by voters in November 2020 and fully operative since January 1, 2023, expanded the original 2018 law. It added the right to correct, created the concept of sensitive personal information, introduced "sharing" for cross-context behavioral advertising, and removed the 30-day cure period that businesses previously relied on to fix violations before enforcement.
Which Businesses Must Honor California Consumer Rights
The CCPA applies to a for-profit entity that does business in California, determines the purposes and means of processing personal information, and meets at least one of the thresholds in Section 1798.140(d):
- Annual gross revenue above $25 million in the preceding calendar year. The CPPA adjusts this figure for inflation, and the adjusted threshold now sits above $26 million.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households. The CPRA raised this from the original 50,000 and removed "devices" from the count.
- Derives 50 percent or more of annual revenue from selling or sharing consumers' personal information.
Two extra categories are covered even without meeting a threshold: entities that control or are controlled by a covered business and share common branding, and joint ventures with covered participants. Non-profits and government agencies are generally outside the scope.
Being under the thresholds does not mean you are unregulated. The California Online Privacy Protection Act (CalOPPA) requires any commercial website collecting personally identifiable information from Californians to post a conspicuous privacy policy, regardless of size. That is why nearly every site needs a privacy policy even when the CCPA itself does not apply.
The Seven California Consumer Rights Explained
1. The Right to Know
Under Sections 1798.100 and 1798.110, consumers can request the categories and specific pieces of personal information a business has collected, the sources it came from, the business or commercial purpose for collecting it, and the categories of third parties that received it. Section 1798.115 adds a parallel right to learn what was sold or shared and to whom.
The original 12-month lookback window is no longer a hard ceiling. Since January 1, 2022, Section 1798.130(a)(2)(B) requires businesses to provide information beyond 12 months on request, unless doing so proves impossible or would involve disproportionate effort.
2. The Right to Delete
Section 1798.105 lets a consumer ask a business to delete personal information collected from them. The business must also direct its service providers, contractors, and, since the CPRA, third parties to whom it sold or shared the data to delete it as well.
Nine exceptions in Section 1798.105(d) allow retention, including completing a transaction, detecting security incidents, exercising free speech, complying with a legal obligation, and internal uses reasonably aligned with the consumer's expectations. You must tell the consumer which exception you relied on rather than silently refusing.
3. The Right to Correct
Added by the CPRA at Section 1798.106, this right lets consumers ask you to fix inaccurate personal information. You must use commercially reasonable efforts to correct it, and you may consider the totality of circumstances and documentation the consumer provides when deciding whether the existing record is in fact inaccurate.
4. The Right to Opt Out of Sale or Sharing
Section 1798.120 gives consumers the right to direct a business not to sell or share their personal information. "Sale" is defined broadly at Section 1798.140(ad) as disclosing personal information to a third party for monetary or other valuable consideration, which is why passing identifiers to an advertising network often counts even when no money changes hands. "Sharing" specifically covers disclosure for cross-context behavioral advertising.
For consumers under 16, the model flips to opt-in. Section 1798.120(c) requires affirmative authorization from a consumer aged 13 to 15, or from a parent or guardian for a child under 13.
5. The Right to Limit the Use of Sensitive Personal Information
Section 1798.121 lets consumers restrict use of sensitive personal information to purposes necessary to deliver the requested goods or services. Sensitive personal information is defined at Section 1798.140(ae) and includes:
- Social Security, driver's license, state ID, and passport numbers
- Account log-in and financial account credentials
- Precise geolocation
- Racial or ethnic origin, religious beliefs, and union membership
- The contents of mail, email, and text messages where the business is not the intended recipient
- Genetic data and biometric information processed to uniquely identify a person
- Health information and data about sex life or sexual orientation
6. The Right to Data Portability
Section 1798.100(d) requires that, where a consumer submits a request to know electronically, the business provide the information in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit it to another entity without hindrance.
7. The Right to Non-Discrimination
Section 1798.125 prohibits denying goods or services, charging different prices, or providing a different level of quality because a consumer exercised their rights. Financial incentives and loyalty programs remain lawful if the difference is reasonably related to the value the data provides to the business and the consumer opts in after clear notice.
How Californians Submit a Rights Request
Section 1798.130(a)(1) requires at least two designated methods for submitting requests to know, including a toll-free telephone number. A business that operates exclusively online and has a direct relationship with the consumer only needs to provide an email address.
Requests can also come from an authorized agent, such as a privacy service acting on the consumer's behalf. You may require the agent to submit proof of authorization and may separately verify the consumer's identity.
Verification is your obligation, not the consumer's problem. The CPPA regulations require you to match the identifying information the consumer provides against data you already hold, and to apply a higher standard, "reasonably high degree of certainty," before disclosing specific pieces of personal information. Requests to opt out cannot be subjected to identity verification at all, because they do not require a verifiable consumer request.
Deadlines for Responding to Rights Requests
Missing a deadline is one of the easiest violations for a regulator to prove, because the timestamps are in your own ticketing system. The core timelines are:
| Request type | Acknowledgement | Substantive response |
|---|---|---|
| Know, delete, correct | 10 business days | 45 calendar days, extendable once by 45 days with notice |
| Opt out of sale or sharing | Not required | 15 business days |
| Limit use of sensitive information | Not required | 15 business days |
| Notify downstream recipients of an opt-out | Not applicable | 90 days from receipt |
If you deny a request in whole or in part, you must explain the basis for the denial. If a request to delete cannot be verified, the regulations direct you to treat it as a request to opt out of sale and sharing instead.
What Your Privacy Policy Must Disclose
Section 1798.130(a)(5) requires a privacy policy updated at least once every 12 months that describes the California consumer rights listed above and explains how to exercise them. At minimum, disclose:
- The categories of personal information collected in the preceding 12 months, and the categories of sources.
- The business or commercial purpose for collecting, selling, or sharing each category.
- The categories of personal information sold or shared, and the categories of third parties that received them.
- The categories of personal information disclosed for a business purpose.
- The retention period for each category, or the criteria used to determine it, a CPRA addition at Section 1798.100(a)(3).
- Whether the business has actual knowledge that it sells or shares the personal information of consumers under 16.
- Two or more methods for submitting requests, plus how an authorized agent can act.
Separately, Section 1798.100(b) requires a notice at collection presented at or before the point of collection. A privacy policy link buried in the footer does not satisfy this if you are collecting sensitive information through a form, so surface the notice next to the form itself. If you need a starting point that already contains the CCPA sections, a privacy policy generator will produce the required disclosures, though you still have to confirm the data map behind them is accurate for your business.
Opt-Out Links and Global Privacy Control
Section 1798.135 gives businesses that sell or share personal information two compliance paths. The first is posting a clear and conspicuous "Do Not Sell or Share My Personal Information" link on the homepage, plus a "Limit the Use of My Sensitive Personal Information" link where applicable. The second is processing opt-out preference signals and disclosing that you do so, in which case the links become optional.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowAn opt-out preference signal is a browser-level setting, most commonly Global Privacy Control (GPC), that communicates the consumer's choice automatically. The CPPA regulations treat a valid signal as a legally binding opt-out request that you must apply to the browser or device, and to the consumer's account if you can associate the two.
Regulators have made this a priority. The Sephora settlement announced by Attorney General Rob Bonta in August 2022 imposed $1.2 million in penalties, in part for failing to honor GPC signals. Later actions, including the CPPA's order against American Honda Motor Co. in March 2025 over an unnecessarily burdensome opt-out flow and the Attorney General's $1.55 million settlement with Healthline in July 2025, show the same pattern: the mechanics of the opt-out matter as much as its existence. Practical details on wording and placement are covered in our guide to the Do Not Sell My Personal Information link.
Enforcement and Penalties for Violating California Consumer Rights
Two enforcement tracks operate in parallel.
Regulatory enforcement. Section 1798.155 authorizes administrative fines of up to $2,500 per unintentional violation and up to $7,500 per intentional violation or any violation involving the personal information of a consumer under 16. Because violations are counted per consumer, exposure scales with your user base rather than with the size of the mistake. Both the Attorney General and the CPPA's Enforcement Division can bring actions.
Private lawsuits. Section 1798.150 gives consumers a private right of action when non-encrypted and non-redacted personal information is exposed in a breach resulting from a failure to maintain reasonable security. Statutory damages run from $100 to $750 per consumer per incident, or actual damages if greater. This is the only part of the CCPA consumers can sue over directly.
The mandatory 30-day cure period disappeared on January 1, 2023 when the CPRA amendments took effect. Regulators may still consider a business's good faith efforts to cure, but they no longer have to give you the chance. For a broader breakdown of operational obligations beyond rights handling, see our CCPA requirements guide.
A Practical Workflow for Handling Rights Requests
Most CCPA failures are operational rather than legal. The policy says the right things; the process behind it does not exist. Build the workflow before the first request arrives:
- Map your data. List every system holding California personal information, including CRM, analytics, support desk, email platform, and ad platforms. You cannot fulfill a request to know if you do not know where the data lives.
- Classify sensitive categories. Flag anything falling under Section 1798.140(ae) so you can respond to limitation requests without a manual audit each time.
- Publish both intake methods. An email address plus a web form is enough for online-only businesses; add a toll-free number if you operate offline.
- Set verification rules in writing. Define what proof you require for a request to know versus a request to delete, and record the decision for each request.
- Log every request with timestamps. Section 1798.130 requires businesses handling the data of 10 million or more Californians a year to publish request metrics; everyone else still needs the log as evidence.
- Test your opt-out end to end. Enable GPC in a browser, load your site, and confirm the advertising tags actually stop firing. A banner that changes state while the pixels keep transmitting is the exact fact pattern regulators have penalized.
- Push deletions downstream. Maintain the list of service providers, contractors, and third parties that must be notified, and hold contracts that obligate them to comply.
A compliance scanner that inventories the cookies, trackers, and third-party services running on your site makes steps one and six far less painful. TermsBox pairs that scanning with hosted documents that update when the scan detects a new tracker, which closes the common gap where a privacy policy silently goes stale after a marketing team adds a tag.
What Is Changing Next
California keeps extending these rights, so treat compliance as ongoing rather than a one-time project. Two developments deserve calendar entries.
The CPPA finalized regulations in 2025 covering automated decision-making technology (ADMT), risk assessments, and cybersecurity audits. They introduce pre-use notices and opt-out rights for certain significant decisions made by automated systems, with the main ADMT obligations phasing in from January 1, 2027.
The Delete Act (SB 362) creates the Delete Request and Opt-Out Platform (DROP), a single portal where Californians can ask every registered data broker to delete their information at once. Registered data brokers begin processing DROP requests in 2026, which is a substantial change if any part of your revenue involves brokering personal information. For a fuller picture of how the amendments reshaped the original law, see our overview of the California Privacy Rights Act.
Frequently Asked Questions
What are my rights as a consumer in California?
California residents have seven privacy rights under the CCPA as amended by the CPRA: the right to know, the right to delete, the right to correct, the right to opt out of the sale or sharing of personal information, the right to limit the use of sensitive personal information, the right to data portability, and the right to non-discrimination. These rights are set out in Civil Code Sections 1798.100 through 1798.125.
Do all businesses have to honor California consumer rights?
No. The CCPA applies to for-profit businesses that do business in California and meet one of three thresholds: more than $25 million in annual gross revenue, buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information. Businesses below all three thresholds are not covered, though other laws such as CalOPPA may still apply.
How long does a business have to respond to a CCPA request?
A business must confirm receipt of a request to know, delete, or correct within 10 business days and respond substantively within 45 calendar days of receiving the request, per Section 1798.130. That deadline can be extended once by another 45 days if the business notifies the consumer of the extension and the reason for it. Opt-out requests must be honored within 15 business days under the CPPA regulations.
What is the penalty for violating California consumer rights?
The California Privacy Protection Agency and the Attorney General can seek administrative fines of up to $2,500 per unintentional violation and $7,500 per intentional violation or violation involving the personal information of a minor under 16, under Section 1798.155. Consumers also have a private right of action for certain data breaches under Section 1798.150, with statutory damages of $100 to $750 per consumer per incident.
Do I have to honor the Global Privacy Control signal?
Yes, if you sell or share personal information. Section 1798.135 and the CPPA regulations require covered businesses to treat an opt-out preference signal such as Global Privacy Control as a valid request to opt out of sale and sharing. California Attorney General Rob Bonta's $1.2 million settlement with Sephora in August 2022 was based in part on the company's failure to process these signals.
Does the CCPA give Californians the same rights as the GDPR?
Not exactly. The CCPA uses an opt-out model for the sale and sharing of personal information, while the General Data Protection Regulation (GDPR) requires opt-in consent before most processing. The CCPA also lacks a general lawful basis requirement, but it adds rights the GDPR does not have, such as the right to limit the use of sensitive personal information.