USCalifornia

CCPA: Consumer Rights

Consumer Rights [§ 1798.100-106]

Rule: California consumers have comprehensive rights over their personal information, including rights to know, delete, correct, port, and opt-out.

Right to Know [§ 1798.100, 110]

Consumers can request disclosure of:

Information TypeDescription
Categories collectedWhat types of PI you collected
SourcesWhere you got the PI
PurposeWhy you collected/used it
Categories sharedWhat types you disclosed to third parties
Third partiesWho received the PI
Specific piecesThe actual data collected about them

Lookback period: 12 months preceding the request (can provide more).

Right to Delete [§ 1798.105]

Consumers can request deletion of their personal information.

Business must:

  1. Delete the PI from records
  2. Direct service providers/contractors to delete
  3. Notify third parties to delete (if sold/shared)

Exceptions — may deny deletion if needed for:

ExceptionExample
Complete a transactionFulfill an order
SecurityDetect security incidents
DebugFix functionality errors
Free speechExercise or defend legal claims
Legal complianceComply with legal obligation
ResearchPublic interest research (with safeguards)
Internal usesReasonably aligned with consumer expectations

Right to Correct [§ 1798.106]

Consumers can request correction of inaccurate personal information.

Business must:

  • Use commercially reasonable efforts to correct
  • Consider the nature of PI and purposes of processing
  • May require documentation supporting correction

Right to Data Portability [§ 1798.100(d)]

When requesting specific pieces of PI, consumers can request data in a:

  • Portable format
  • Readily useable format
  • Format allowing transmission to another entity without hindrance

Right to Opt-Out of Sale/Sharing [§ 1798.120]

Consumers have the right to direct a business to not sell or share their personal information.

  • Business must respect opt-out
  • Must provide “Do Not Sell or Share My Personal Information” link
  • Must honor Global Privacy Control (GPC) signals
  • Cannot require account creation to opt-out

Right to Limit Sensitive PI Use [§ 1798.121]

Consumers can direct businesses to limit use of sensitive personal information to:

  • Performing services/providing goods requested
  • Ensuring security and integrity
  • Short-term transient use (non-profiling)
  • Performing services on behalf of business
  • Verifying/maintaining quality
  • Other purposes where opt-out not permitted

Right to Non-Discrimination [§ 1798.125]

Businesses cannot discriminate against consumers who exercise rights:

ProhibitedAllowed
Denying goods/servicesOffering financial incentives for data
Charging different pricesPrice differences reflecting data value
Providing different qualityLoyalty programs with notice
Threatening any of the aboveDifferential service if data necessary

Authorized Agents [§ 1798.140(e)]

Consumers can designate an authorized agent to make requests on their behalf.

Business can require:

  • Written permission from consumer
  • Direct verification of consumer identity
  • Agent registration with Secretary of State (for opt-out)

Exercising Rights — Response Timeline

StepTimeline
Confirm receiptWithin 10 business days
Respond to requestWithin 45 calendar days
Extension (if needed)Additional 45 days with notice
DenialMust explain reasons and appeal rights

Citation

§§ 1798.100-106, California Civil Code

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt