Artifact GuideUSCorrection Rights

US CPRA Correction Rights

Use this guide to resolve Correction Rights under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A California consumer may ask a covered business to correct inaccurate personal information that it maintains. Confirm receipt within 10 business days, verify the request under the regulations, decide accuracy from the , and respond within 45 calendar days unless a permitted extension applies. A correction must reach active systems and the service providers and contractors that maintain the information.

Section 1

What should teams decide about Correction Rights under the US CPRA?

First identify the contested information and every system that maintains it. Confirm whether the request came from the consumer or an authorized agent, apply the required verification standard, and avoid collecting new identity information unless necessary. If identity cannot be verified, the business may deny the request but must tell the requester that verification failed.

Decide accuracy from the , including whether the information is objective or subjective, how the business obtained it, and documentation from the consumer, the business, or another source. The business may deny the request if the contested information is more likely than not accurate. If the business is not the source and has no supporting documentation, the consumer's assertion may be enough to establish inaccuracy.

The statute requires commercially reasonable efforts to correct inaccurate information. The regulations also allow a business to delete the contested information instead when deletion will not negatively affect the consumer or when the consumer consents. If deletion could make it harder to obtain employment, housing, credit, education, or another opportunity, correct the information or obtain consent before deleting it.

  • Log the request date, intake method, contested field, affected account or record, verification result, and response deadline.
  • Accept, review, and consider the consumer's documentation. Request additional documentation only when necessary under the regulatory factors and protect it with reasonable security.
  • Identify the authoritative record, derived copies, active systems, and service providers or contractors that maintain the information.
  • Record the accuracy decision, correction or deletion action, downstream instructions, response, denial basis, reviewer, and completion evidence.
Section 2

What happens when the business grants the request?

Correct the information in existing active systems and instruct each service provider or contractor that maintains it under the written contract to make the correction or enable the business to do so. Archived or backup copies may wait until the relevant system is restored, accessed, or used.

Tell the consumer whether the request was completed. If the consumer asks, disclose the specific pieces maintained and collected about them so they can confirm the correction; for Social Security numbers, government identifiers, financial or medical account numbers, passwords, security answers, and unique biometric data, provide a confirmation method without disclosing the sensitive value itself. The case file should show the old and corrected value where retaining that comparison is necessary and lawful, each affected system and recipient, the instruction date, completion status, and any backup-system dependency.

Privacy operations should own the case and timing. The data owner decides the authoritative value, engineering or operations changes systems, recipient owners transmit instructions, and privacy or legal reviews exceptions, material disputes, and denials.

  • Send the 10-business-day confirmation and preserve the delivery record.
  • Complete the response within 45 calendar days or notify the consumer of the permitted extension during the initial period and explain why it is needed.
  • Track active-system corrections and instructions to service providers and contractors to completion.
  • Retain the request and response record for at least 24 months, including the basis for any partial action.
Section 3

When may the business deny or limit correction?

A denial may rest on failed verification, a finding that the information is more likely than not accurate, a statutory exemption, inadequate required documentation, impossibility, or disproportionate effort. The response must explain the basis. A bare statement that correction is impossible or burdensome is not enough.

A business that denied the same alleged inaccuracy within the previous six months may deny a repeat request, but it must treat the request as new when the consumer provides new or additional documentation. If the business denies correction of personal information collected and analyzed concerning the consumer's health, it must explain that the consumer may request a written statement in the record. The statement is limited to 250 words for each alleged inaccuracy and, once received with the required request, must be included with the consumer's record.

Disproportionate effort is a request-specific test that compares the time and resources needed with the reasonably foreseeable effect on the consumer. A business cannot rely on its failure to build adequate request processes as the reason the effort is disproportionate.

  • Explain each denial and cite the conflict, exception, documentation issue, accuracy finding, impossibility, or disproportionate-effort facts.
  • Do not ask for excessive documentation or use documentation obtained for correction for an unrelated purpose.
  • Separate factual inaccuracy from a disagreement with an opinion, model output, or lawful business decision, while still considering how the information was created and used.
  • Correct unaffected portions when only part of the request is denied and tell the consumer what was and was not changed.
Section 4

How should teams test the correction workflow?

Test with representative records that appear in a primary database, derived profile, analytics store, customer-support tool, service provider, and backup. Confirm that intake starts the deadline, verification is proportionate, evidence reaches the data owner, and the final response matches the recorded outcome.

The workflow should prevent corrected information from being overwritten by an unchanged source or reintroduced through a batch import. Record the authoritative source and any synchronization, model, or enrichment process that must change.

  • Verify that the public request method accepts correction requests without steering consumers to another right.
  • Measure the 10-business-day confirmation and 45-calendar-day response from receipt, not from internal assignment.
  • Trace one granted request through every active system and contracted recipient, test the consumer's confirmation path without exposing restricted identifiers, and confirm the backup rule is documented.
  • Trace one denied request and confirm the case file supports the explanation, partial correction, repeat-request rule, and retention record.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • California statute establishing the consumer right to request correction and the business duty to use commercially reasonable efforts after a verifiable request.
"A consumer shall have the right to request a business that maintains inaccurate personal information about the consumer to correct that inaccurate personal information."
cppa.ca.gov
Referenced sections
  • CPPA regulations source for operational response rules that implement CCPA/CPRA consumer requests, including right-to-correct workflows.
"A business may deny a consumer’s request to correct if it determines that the contested personal information is more likely than not accurate based on the totality of the circumstances."
cppa.ca.gov
Referenced sections
  • CPPA public FAQ context confirming CPRA added consumer rights and business obligations under the CCPA framework.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses."
nist.gov
Referenced sections
  • Voluntary, non-binding NIST privacy-risk guidance; it does not establish CCPA correction duties.
"The NIST Privacy Framework (PF) is a voluntary tool developed in collaboration with stakeholders intended to help organizations identify and manage privacy risk to build innovative products and services while protecting individuals’ privacy."
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.