Skip to content
Coverage

Data rights

California Consumer Privacy Act (as amended by the CPRA)

Sub-nationalUS-CARead off primary law

California, United States

Rule id
data.us-ca
Version
1.1.0
In force from
January 1, 2020
Last read against its sources
August 5, 2026
Countries bound
United States

In plain language

What this regime says.

The CCPA gives Californians access, deletion, correction and opt-out rights with a 45-day deadline, and — uniquely in the United States — a private right of action, but only for data breaches.

Who is covered

California residents, including employees and job applicants, dealing with a business that meets one of the thresholds (broadly: USD 25m+ revenue, 100,000+ consumers, or 50%+ of revenue from selling or sharing personal information).

What you get

Your data, its deletion, and an opt-out from sale and sharing. Money only where a breach of your unencrypted data was caused by inadequate security: USD 100–750 per consumer per incident.

Where claims go wrong

  • Believing you can sue over a late access request. You cannot. § 1798.150 covers breaches only.
  • Letting verification eat the 45 days. The clock runs from receipt of your request, not from verification.
  • Writing a letter instead of enabling Global Privacy Control, which a business must honour automatically.
  • Accepting "we do not sell your data" without asking whether they SHARE it for cross-context behavioural advertising.
The official claim route

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. Cal. Civ. Code § 1798.100 et seq. (California Consumer Privacy Act, as amended by the CPRA)California Civil Code, Division 3, Part 4, Title 1.81.5URL verified 2026-08-05§§ 1798.100–1798.199.100
  2. Cal. Civ. Code § 1798.130(a)(2) — 45 days to respond, extendable by a further 45California Civil CodeURL verified 2026-08-05§ 1798.130(a)(2)
  3. Cal. Civ. Code § 1798.150 — private right of action for data breaches, USD 100–750 per consumer per incidentCalifornia Civil CodeURL verified 2026-08-05§ 1798.150(a)(1)(A)
  4. 11 CCR § 7025 — opt-out preference signals must be treated as a valid request to opt outCalifornia Code of Regulations, Title 11, Division 6URL verified 2026-08-05§ 7025

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • California Consumer Privacy Act (as amended by the CPRA): deadline for the controller to respond§ 1798.130(a)(2): the business must respond promptly and in any event within 45 days of receiving a verifiable consumer request. The 45 days runs from receipt of the request, not from when you were verified.Cal. Civ. Code § 1798.130(a)(2) — 45 days to respond, extendable by a further 45 — § 1798.130(a)(2)Response due
  • California Consumer Privacy Act (as amended by the CPRA): extended deadline if the controller notified an extension§ 1798.130(a)(2) allows one further 45-day extension where reasonably necessary, but the business must tell you within the first 45 days, with the reason. The outside limit is therefore 90 days.Cal. Civ. Code § 1798.130(a)(2) — 45 days to respond, extendable by a further 45 — § 1798.130(a)(2)Response due

What it entitles you to, beyond money

  • Compliance with your access requestThree separate rights that most people ask for as one, and you should ask for all three by name: § 1798.110 (the categories and SPECIFIC PIECES of personal information collected, the sources, the business purpose, and the categories of third parties); § 1798.115 (the categories sold or shared, and to whom); and § 1798.100 (access to the information itself). Asking for "my data" gets you less than asking for these three.§§ 1798.100, 1798.110, 1798.115
  • Automatic opt-out via Global Privacy ControlEnable Global Privacy Control in your browser or extension. Under 11 CCR § 7025 a business must treat the signal as a valid request to opt out of the sale and sharing of your personal information — no verification, no letter, no 45-day wait, and it applies to every site you visit rather than one company at a time.§ 7025

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

Verification used to run out the clock

high likelihood

We need to verify you before we can respond. Please complete this identity check.

What answers it

Verification is required, but the 45 days runs from the date the business RECEIVED your request — not from the date it finished verifying you. Reply to the verification promptly, and if the response then arrives after day 45 counted from your original request, say so explicitly. The regulations also cap what a business may ask for: it must not collect new personal information from you for verification if it can match against what it already holds.

Cal. Civ. Code § 1798.130(a)(2) — 45 days to respond, extendable by a further 45 — § 1798.130(a)(2)

"We do not sell your personal information"

high likelihood

We do not sell personal information, so there is nothing for you to opt out of.

What answers it

The CPRA added "sharing" precisely because of this answer. "Sharing" means disclosure for cross-context behavioural advertising, whether or not money changes hands. Ask specifically: do you SHARE personal information for cross-context behavioural advertising? Any site running third-party ad tech almost certainly does, and the "Do Not Sell or Share My Personal Information" link is mandatory where it does.

Cal. Civ. Code § 1798.100 et seq. (California Consumer Privacy Act, as amended by the CPRA) — §§ 1798.100–1798.199.100

"We are not a covered business"

high likelihood

We do not meet the applicability thresholds in your state's law, so we are not required to respond to your request.

What answers it

Make them say which threshold they fall under, in writing. The thresholds differ sharply between states — Texas and Nebraska use a small-business test rather than a revenue figure, Montana and Delaware have low consumer-count thresholds, and a company that sells personal data is usually covered at a much lower volume. A business that will not identify the threshold it relies on is worth reporting to the Attorney General for exactly that reason.

They ignore the appeal too

high likelihood

(silence)

What answers it

Good. Almost every one of these statutes requires the controller, when it denies an appeal, to give you a written explanation AND a mechanism to contact the Attorney General. Silence on an appeal is therefore two violations, not one, and it converts a complaint about a request into a complaint about the statutory appeal machinery — which is the sort of thing enforcement divisions actually act on.

Endless identity verification

high likelihood

We cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.

What answers it

A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.

"We hold no personal data about you"

high likelihood

A search of our systems returned no personal data relating to you.

What answers it

Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.

Global Privacy Control quietly ignored

medium likelihood

(no response — the site simply does not act on the signal)

What answers it

11 CCR § 7025 requires a business to treat an opt-out preference signal as a valid request to opt out of sale and sharing. Ignoring GPC is a discrete, demonstrable violation, and it is the fact pattern the CPPA and the Attorney General have publicised enforcement on. Take a screenshot showing the signal enabled and the site still setting advertising cookies, and report it.

11 CCR § 7025 — opt-out preference signals must be treated as a valid request to opt out — § 7025

"We are only a service provider / processor"

medium likelihood

We process this data on behalf of our business customers. Direct your request to them.

What answers it

A processor still has to assist the controller and, in most of these statutes, to help the consumer reach the controller. Ask for the identity and contact details of the controller. If they will not tell you who they process for, they are asserting a status whose only condition they refuse to evidence.

Blanket confidentiality or trade-secret refusal

medium likelihood

The information you have requested is commercially confidential / contains our trade secrets / is proprietary.

What answers it

Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.

Refusal because the data mentions someone else

medium likelihood

We cannot disclose these records because they contain the personal data of other individuals.

What answers it

The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.

"Your request is manifestly excessive"

medium likelihood

Your request is manifestly unfounded or excessive, so we are refusing it / charging a fee.

What answers it

The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.

Where to take it next

  1. Written request to Sample ControllerSend it to the named data-protection contact or privacy team, in writing, and keep proof of the date. If the organisation has a designated Data Protection Officer, address it to them by title. Use the word "request" and name the right you are exercising.Claim directtypically 45 days
  2. Complain to the California Privacy Protection AgencyThe CPPA is a dedicated privacy regulator with rulemaking and enforcement powers — the only one of its kind in the United States. It takes consumer complaints directly. This is a materially better route than a generic state AG complaint because the agency does nothing else.Regulatortypically 120 daysofficial page
  3. Small claims or civil action under § 1798.150 — data breaches onlyIf your data was exposed in a breach caused by inadequate security, § 1798.150 gives USD 100–750 per incident without proof of loss. Send the 30-day cure notice first; it is a statutory precondition to statutory damages. This does not help with a mishandled access request.Courttypically 240 days
  4. Complain to the California Privacy Protection Agency (CPPA) and the California Attorney Generalthe California Privacy Protection Agency (CPPA) and the California Attorney General takes complaints from individuals about a specific organisation's handling of a specific request. It is free. Attach your original request, proof of the date you sent it, and anything the organisation sent back.Regulatortypically 120 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Other rights in the same countries

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.