Artifact GuideUSPersonal and Sensitive PI Categories
US CCPA Personal and Sensitive PI Categories
Classify personal information and sensitive personal information by the statutory definitions, then map collection, use, disclosure, retention, sale, sharing, limitation rights, and security controls.
Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.
Classify information by what it can reasonably identify, describe, or link to a consumer or household, not by its database label. is a defined subset of with additional notice and limit-use consequences. Use this guide to separate covered data from statutory exclusions and to connect each category to the controls it changes.
1
Section 1
What should teams decide about Personal and Sensitive PI Categories under the US CCPA?
Start by identifying what the CCPA treats as and . Personal information is information that identifies, relates to, or could reasonably be linked to a particular consumer or household, and the CCPA gives examples such as a name, email address, records of products purchased, internet browsing history, geolocation data, fingerprints, and inferences about preferences and characteristics.
is a narrower set that includes government identifiers; account credentials or financial-account access information; ; racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, and mail, email, or text contents when the business is not the intended recipient; genetic data; biometric information processed to identify a consumer; and collected and analyzed about health, sex life, or sexual orientation. Under the regulations effective January 1, 2026, it also covers personal information of consumers the business has actual knowledge are under 16.
Publicly available, lawfully obtained truthful information that is a matter of public concern, and deidentified or aggregate consumer information are excluded from under specific statutory conditions. A record does not become excluded merely because it can be found online or because direct identifiers were removed.
Identify the actual data element, how it is obtained, the consumer or household link, and whether it is used to infer another characteristic.
Check the sensitive-personal-information definition element by element; sensitivity in ordinary speech is not the legal test.
Test any public-information or deidentification exclusion against all statutory conditions and document the source and safeguards.
Map the final category to notice, access, deletion, correction, retention, security, sale, sharing, and limit-use controls.
Who should own Personal and Sensitive PI Categories, and what evidence should prove the decision?
Data owners should describe the field and use; privacy or legal should approve classification and exclusions; engineering and security should map systems and safeguards; and product, marketing, and procurement should document recipients and sale or sharing.
Keep a data dictionary, sample values or schemas that avoid unnecessary live , source, purpose, retention, recipients, inference logic, classification rationale, and links to the notices and rights workflows affected.
Record whether is used only for purposes allowed by the regulations or whether the right to limit must be offered.
Treat inferences as their own data product when the business creates a profile about preferences, characteristics, behavior, attitudes, abilities, or similar traits.
Reclassify when a field is combined with new identifiers, used for identification, or analyzed to reveal a protected characteristic.
Review category maps when collection, models, vendors, retention, or disclosure purposes change.
Which edge cases should teams check before relying on a Personal and Sensitive PI Categories decision?
Biometric information is when processed for the purpose of uniquely identifying a consumer. A photograph, voice recording, or keystroke pattern still may be even when that sensitive-category test is not met.
means a location derived from technology that identifies a consumer within a geographic area no larger than a circle with a radius of 1,850 feet, subject to the statutory exception for certain content of communications. General city or region information may remain without meeting that precise-geolocation test. Message content is sensitive only when the business is not the intended recipient, while metadata may fit other personal-information categories.
Do not classify encrypted or hashed identifiers as deidentified without the required technical and organizational measures against reidentification.
Do not omit household information merely because no named individual is present.
Do not treat an inference as outside scope because its underlying source data was public.
Do not assume a sectoral exemption covers the entire entity; many CCPA exemptions attach to specified information or activities.
How should teams operationalize Personal and Sensitive PI Categories with proportionate controls?
Classify at field and use-case level, then group fields into consumer-facing CCPA categories for notices and rights responses. The internal record should remain specific enough to reproduce the classification and locate the data.
Apply a change trigger whenever a team adds an identifier, creates an inference, changes a biometric or location use, combines data sets, or changes a recipient or purpose.
Describe the data element, source, linkability, processing purpose, and any inferred characteristic.
Apply the personal-information definition, then the sensitive subset and each claimed exclusion.
Record systems, retention, recipients, sale or sharing, allowed sensitive uses, and affected rights.
Update notices and controls before introducing a new category or materially different use.
Turn US CCPA Personal and Sensitive PI Categories into assigned work
This US CCPA guide turns Personal and Sensitive PI Categories into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Non-binding CPPA FAQ explaining the public-facing distinction between personal information, sensitive personal information, and the right to limit sensitive-information use.
"Personal information includes sensitive personal information"